# Path lexical sanitize

`path-lexical-sanitize` · version 1.0.0 · File paths (lexical) · free, no key needed

Sanitize an untrusted path to produce a safe relative path, stripping roots, drive letters, traversal segments, and illegal characters.

**Use when you need to: sanitize path · path security sanitize · safe relative path.**

## Supported

- sanitize path
- path security sanitize
- safe relative path
- strip path traversal
- strip illegal filename characters

## Not supported

- stat file
- resolve symlinks
- filesystem access
- guarantee filesystem safety on all OS versions

## Behavior

- Strip drive letters and UNC roots. Resolve and collapse ".." to prevent escape above implicit base. Strip null bytes, illegal chars (< > : " | ? * and control 0x00-0x1F, 0x7F). Replace Windows reserved names. If allow_dots is false, strip leading-dot segment names. was_safe: true if no changes were needed.

## Input

- `path` (string, required): max length 4096
- `replacement` (string, optional): max length 64
- `allow_dots` (boolean, optional)

## Output

- `sanitized` (string, required)
- `was_safe` (boolean, required)
- `changes` (array of string, required)

## Limits

- max path bytes: 4096
- max replacement bytes: 64

## Example

Request input:

```json
{
  "path": "safe/relative/file.txt"
}
```

Response:

```json
{
  "result": {
    "sanitized": "safe/relative/file.txt",
    "was_safe": true,
    "changes": []
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "path-lexical-sanitize",
  "version": "1.0.0",
  "input": {
    "path": "safe/relative/file.txt"
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/path-lexical-sanitize/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"path":"safe/relative/file.txt"}'
```

The machine-readable contract is at [/v1/tools/path-lexical-sanitize/versions/1.0.0](/v1/tools/path-lexical-sanitize/versions/1.0.0).

### CLI

```sh
node cli.mjs run path-lexical-sanitize 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Path lexical contains](/tools/path-lexical-contains): Check whether a child path is lexically inside a parent directory.
- [Path lexical relative](/tools/path-lexical-relative): Compute the lexical relative path from one path to another without filesystem access.
- [Path lexical common ancestor](/tools/path-lexical-common-ancestor): Compute the deepest common ancestor directory of a set of paths.
- [Path lexical join](/tools/path-lexical-join): Join an array of path segments lexically, resolving absolute reset boundaries and normalizing separators.
- [Path lexical normalize](/tools/path-lexical-normalize): Normalize a path lexically: collapse redundant separators, resolve "." and ".." segments.
- [Path lexical parse](/tools/path-lexical-parse): Decompose a file path into its lexical components without accessing the filesystem.
