Glossary · Term

input sanitization

← all terms

Definition

Plain language

Cleaning up incoming data to strip out anything that could be misread as a command.

As stated in the literature

Filtering, escaping, or removing untrusted content before it reaches a downstream interpreter or model context; in multimodal settings this can mean detecting and masking text regions in an image.

Also called: sanitization, sanitized, sanitize

Why it matters: It is often the cheapest first line of defense against injected commands, though it works by guessing what looks dangerous rather than by structurally separating data from instructions.

For example, a customer-support system might strip out phrases like "ignore previous instructions" from an uploaded document before passing the text into the model's context.

Heard on the show

“When an agent wants to know "does any code path from this web form reach the database without input sanitization," it doesn't search files.”
Episode 039 — When Smarter Agents Get Fooled by Three Extra Nodes in a Database

Related terms