---
name: velin-security-sanitize-html
description: Review/sanitize untrusted HTML per VelinStyle security guidance; review.security — not agent briefing.
---
# Sanitize HTML (Security Review)

## Purpose
Applies safe HTML sanitization guidance for dynamic content.

## Domain
R · category `security`

## Capabilities
- `review.security`

## Permission
`review-only`

## Allowed actions
- READ
- ANALYZE
- RECOMMEND

## Forbidden actions
- WRITE
- APPLY
- ROLLBACK
- ACCEPT
- DEFER
- NOTE
- ACKNOWLEDGE
- CATALOG
- MANIFEST
- CLASSIFY
- invent-target

## Stop conditions
- SR-03
- SR-11

## Agent role / risk
Security · risk `med`

## Purpose
Security review skill for HTML sanitization concerns (`review.security`). Identify unsafe markup patterns and recommend safe handling. **Not** AI briefing, not migration mapping, not rewrite Apply.

## Workflow
1. READ/ANALYZE provided HTML.
2. Flag script/event-handler/unsafe URL patterns per project security policy.
3. Recommend sanitize steps; do not invent migration targets.
4. Permission remains review-oriented — no silent rewrite Apply of class migrations.

## Rules
- Fail closed on uncertainty (SR-03/11).
- Do not conflate with `velin-ai-agent-briefing`.

## Anti-patterns
- Using sanitize as a vehicle to auto-map Tailwind classes.

## Inputs / Outputs
- Inputs: html
- Outputs: diff, report
