webcit: sanitize instant messages against XSS type stuff