
Mdx Sanitizer
- 138 installs
- 178 repo stars
- Updated July 14, 2026
- erichowens/some_claude_skills
Sanitize untrusted MDX before render to block XSS, unsafe components, and malicious embeds in docs sites, blogs, and CMS-driven content platforms.
About
MDX sanitizer skill for securing content rendering pipelines against XSS and unsafe embedded components in documentation sites, marketing blogs, and CMS platforms. Use before shipping features that compile or render MDX from authors, imports, or third-party sources.
- Blocks XSS in MDX content pipelines
- Component and import allowlisting
- Protects docs, blogs, and CMS renders
- Handles untrusted author submissions
- Pre-launch content security hardening
Mdx Sanitizer by the numbers
- 138 all-time installs (skills.sh)
- Ranked #922 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 4, 2026 (Skillselion catalog sync)
npx skills add https://github.com/erichowens/some_claude_skills --skill mdx-sanitizerAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 138 |
|---|---|
| repo stars | ★ 178 |
| Last updated | July 14, 2026 |
| Repository | erichowens/some_claude_skills ↗ |
What it does
Sanitize untrusted MDX before render to block XSS, unsafe components, and malicious embeds in docs sites, blogs, and CMS-driven content platforms.
Files
MDX Sanitizer
Comprehensive MDX content sanitizer that prevents JSX parsing errors caused by angle brackets, generics, and other conflicting patterns.
The Problem
MDX 2.x treats unescaped < and { as JSX syntax. This causes build failures when content contains:
- TypeScript generics:
Promise<T>,Array<string>,Map<K, V> - Comparisons:
<100ms,<=,>= - Arrows:
-->,<--,-> - Invalid tags:
<link>in prose,<tag>placeholders - Empty brackets:
<>
Solution Architecture
This skill implements a three-layer defense:
1. Sync-Time Sanitization (Proactive)
Content is sanitized when syncing from .claude/skills/ to website/docs/:
syncSkillDocs.ts- Main skill filessyncSkillSubpages.ts- Reference filesdoc-generator.ts- Generated docs
2. Pre-Commit Validation (Reactive)
The git pre-commit hook validates files before commit using validate-brackets.js.
3. Build-Time Validation (Final Check)
npm run validate:all runs as part of prebuild to catch any issues.
Usage
Check for Issues (Dry Run)
cd website
npm run sanitize:mdx
# or with verbose output
npm run sanitize:mdx -- --verboseFix All Issues
cd website
npm run sanitize:mdx -- --fix
# or shorthand
npm run fix:mdxProgrammatic API
import { sanitizeForMdx, validateMdxSafety, isMdxSafe } from './lib/mdx-sanitizer';
// Sanitize content
const result = sanitizeForMdx(content, { useHtmlEntities: true });
if (result.modified) {
console.log(`Fixed ${result.issues.length} issues`);
fs.writeFileSync(path, result.content);
}
// Validate without modifying
const issues = validateMdxSafety(content, 'path/to/file.md');
// Quick check
if (!isMdxSafe(content)) {
// Handle issues
}Escaping Strategies
The sanitizer uses HTML entities for maximum compatibility:
| Pattern | Original | Escaped |
|---|---|---|
| Less-than | < | < |
| Greater-than | > | > |
| Generics | <T> | &lt;T&gt; |
| Comparison | <= | &lt;= |
Content inside code blocks (` ` or ``) is automatically protected and never escaped.
Files Modified
website/scripts/lib/mdx-sanitizer.ts- Core sanitizer modulewebsite/scripts/sanitize-mdx.ts- CLI wrapperwebsite/scripts/syncSkillDocs.ts- Integrationwebsite/scripts/syncSkillSubpages.ts- Integrationwebsite/scripts/lib/doc-generator.ts- Integrationwebsite/package.json- npm scripts
Patterns Detected
1. Less-than before digit: <100, <0.5ms 2. Comparison operators: <=, >= 3. Empty brackets: <> 4. Arrows: <--, --> 5. Generic types: Promise<T>, Array<string> 6. Space after less-than: < value 7. Invalid pseudo-tags: <link>, <tag> (not valid HTML)
Troubleshooting
Build Still Fails After Running Sanitizer
1. Clear Docusaurus cache: npm run clear 2. Re-run sanitizer: npm run sanitize:mdx -- --fix 3. Rebuild: npm run build
False Positives
If valid JSX components are being escaped:
- Ensure they use PascalCase (e.g.,
<MyComponent>) - Check they're valid HTML5 elements
Manual Escaping
For edge cases, manually escape in source:
- Use backticks for inline code: `
<T>` - Use fenced code blocks for multi-line
- Use HTML entities:
<and>