Rendered inert
An artifact is content the agent produced — from data it read, which may itself be untrusted — so it is never trusted to run. Displaying one safely is defense in depth: sanitize the bytes, constrain them with a policy, and isolate the origin they're served from.
Sanitize
Each renderer cleans its own content type. HTML is run through a strict sanitizer that strips scripts and
disallows dangerous constructs; CSS and SVG pass through their own sanitizers (no @import, no script-bearing
SVG); images are decoded and re-encoded to strip any embedded metadata. The cleaning is baked into the
render, not left to whatever surface later shows the artifact.
Constrain
On top of sanitizing, an HTML artifact is served under a strict Content-Security-Policy baked into the document — no external loads, and a sandbox directive that disables scripts for the document itself. Even content that slipped past the sanitizer has nothing to reach and no way to execute in place.
Isolate
Finally, an artifact is served from a separate sandbox origin — never the trusted app origin — and nested inside a sandboxed iframe that does not permit scripts. So an artifact's own JavaScript structurally cannot run in the context of the app that displays it: the sanitizer is the first layer, the CSP the second, and the origin isolation the backstop that holds even if the first two are wrong.