Would that be a good way to sanitise user input? Like removing script tags etc...

It’s usually not a good idea to “get creative” when it comes to security

Only if you trust Pandoc enough to expose it to unsanitised user input.

