affaan-m/ECC · error
must not contain control or bidirectional formatting…
Error message
${label} must not contain control or bidirectional formatting characters. What it means
After trimming and length checks, asNonEmptyString scans for unsafe control characters and bidirectional formatting characters (e.g. U+202E RTL overrides) that could corrupt display or enable Trojan-source style spoofing. Any validated memory-vault string containing them is rejected.
Solutions
- Strip control and bidi characters from the input, e.g. value.replace(/[\u0000-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '').
- Sanitize user input at the boundary before passing to the vault.
- Re-copy the text from a clean source if it was pasted from a PDF/terminal.
- For bidi content, store a plain-text normalization rather than raw directional marks.
Example fix
// before asNonEmptyString(pastedText, 'content') // after const clean = pastedText.replace(/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '') asNonEmptyString(clean, 'content')
Defensive patterns
Strategy: validation
Validate before calling
// eslint-disable-next-line no-control-regex const UNSAFE = /[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g const sanitized = String(raw).replace(UNSAFE, '')
Type guard
function isSafeText(v) {
// eslint-disable-next-line no-control-regex
return typeof v === 'string' && !/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/.test(v)
} Try / catch
try {
asNonEmptyString(value, 'content')
} catch (err) {
if (err.message.includes('control or bidirectional')) {
value = value.replace(/[\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F\u200B-\u200F\u202A-\u202E]/g, '')
} else throw err
} Prevention
- Sanitize all pasted/external text before storing in the vault.
- Strip control and bidi characters at input boundaries (clipboard, file import).
- Treat RTL-override characters in user input as suspicious (Trojan-source defense).
- Re-copy text from clean sources rather than pasting from PDFs/terminals.
When it happens
Trigger: Passing a string containing control characters (e.g. \u0000-\u001F other than allowed whitespace, \u007F) or bidi marks (\u200F, \u202E, etc.) to asNonEmptyString via normalizeMemory or resolveOverride.
Common situations: Pasting text from PDFs or terminals that embed control characters; malicious input crafted with RTL overrides to reverse visual display; binary data accidentally decoded as a string; filenames or logs copied with stray \x1b escape sequences.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- memory body must not contain unsafe control or…
- Refusing to save memory containing a suspected secret
- artifact path escapes output directory
- artifact permits provider execution
- download requires HTTPS on an approved fal.media host
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/2efe4998e8dbc35d.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/lib/memory-vault-format.js:86
|| (codePoint >= 0x7f && codePoint <= 0x9f);
const isBidirectionalFormatting = (
(codePoint >= 0x202a && codePoint <= 0x202e)
|| (codePoint >= 0x2066 && codePoint <= 0x2069)
);
return isControl || isBidirectionalFormatting;
});
}
function asNonEmptyString(value, label, maxChars = 10_000) {
if (typeof value !== 'string' || value.trim().length === 0) {
throw new Error(`${label} must be a non-empty string.`);
}
const normalized = value.trim();
if (normalized.length > maxChars) {
throw new Error(`${label} is too long (maximum ${maxChars} characters).`);
}
if (hasUnsafeControlCharacters(normalized)) {
throw new Error(`${label} must not contain control or bidirectional formatting characters.`);
}
return normalized;
}
function validateEnum(value, allowed, label) {
const normalized = asNonEmptyString(value, label, 64);
if (!allowed.includes(normalized)) {
throw new Error(`${label} must be one of: ${allowed.join(', ')}.`);
}
return normalized;
}
function validateSlug(value, label) {
const normalized = asNonEmptyString(value, label, 64);
if (!SLUG_PATTERN.test(normalized)) {
throw new Error(`${label} must be a lowercase letters/numbers slug.`);
}
return normalized;View on GitHub (pinned to 8321021c54)