Skip to content

Cite with markdown links and stop rendering HTML in the chat - #307

Merged
adamjohnwright merged 1 commit into
mainfrom
markdown-citations
Oct 3, 2026
Merged

adamjohnwright merged 1 commit into
mainfrom
markdown-citations

Conversation

@adamjohnwright

Copy link
Copy Markdown
Contributor

unsafe_allow_html = true was the root cause behind both HTML-injection findings from the area 1b review. It was needed only because answers cited sources with <a href> anchors. Citations are now markdown links, and HTML rendering is off.

Measured

The answer sweep's 16 questions, run twice each through the real graph:

Before After
Cited answers 24/32 24/32
Answers with HTML anchors 24 0
Answers with markdown links 7 24
## Sources heading present 24 24

The same four answers are uncited before and after: the off-topic and medical refusals, and the live-data release and species answers. The full sweep passes 16/16.

Changes

  • Five prompts (Reactome, user guide, UniProt, Plant Reactome, cross-database summariser) now ask for [Name](URL).
  • MarkdownLinkStripper: the search page's prose gets labels only, as it did for anchors. It is a streaming stripper that holds back only from a [ that could still become a link. Tested at single-character fragments.
  • unsafe_allow_html = false.
  • Directive colons. Chainlit's renderer includes remark-directive, which reads :p25 in "CDK5:p25" as markup and drops it. Anchors had hidden this inside link labels, but prose always had the problem. escape_directives now runs on finished answers, and inside escape/inert_html.

Verified in a browser

  • Citation links: 18 citations render as clickable links, and no ](http or <a href appears as text.
  • Colon names: "CDK5:p25" stays intact.
  • Injected markup: with the handoff escaping removed and HTML off, injected markup still renders as text with 0 live elements. So HTML-off closes the class on its own.
  • Regression suites: the analysis handoff and gene-list suites still pass.

🤖 Generated with Claude Code

The chat rendered HTML because answers cited with <a href> anchors, and
that let any markup that reached a message run in the reader's browser
(review, area 1b). Citations are now markdown links and
unsafe_allow_html is false, which closes the whole class.

- Five prompts ask for [Name](URL) instead of <a href="URL">Name</a>.
  Measured on the answer sweep's 16 questions, twice each: cited answers
  24/32 before and after; HTML anchors 24 -> 0; markdown links 7 -> 24;
  Sources heading 24 -> 24. Full sweep 16/16.
- The search page's answer stream strips markdown links to their labels,
  as it strips anchors (kept, in case one slips through).
- Chainlit's renderer includes remark-directive, which read the ':p25' in
  'CDK5:p25' as markup and dropped it. Anchors had hidden this in link
  labels; prose always had it. Directive-shaped colons are now escaped in
  finished answers and wherever names are written into chat messages.

Checked in a browser: citations render as clickable links, no markdown or
HTML syntax shows as text, 'CDK5:p25' stays intact; with the handoff
escaping removed and HTML off, injected markup still renders as text.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@adamjohnwright
adamjohnwright merged commit 0544fc9 into main Oct 3, 2026
10 checks passed
@adamjohnwright
adamjohnwright deleted the markdown-citations branch October 3, 2026 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant