Thanks for your feedback! I see input sanitation as a double-edged sword: it could potentially prevent some misuse of the service (since it's 100% anonymous), but then ultimately you're the "owner" of your keys (though they're in reality public) and you should be able to write whatever you want in them.
I guess this argument could also be applied to Pastebin? Should it be returning raw HTML if asked to?
I guess this argument could also be applied to Pastebin? Should it be returning raw HTML if asked to?