# 2026-09-28 — A posted doc could run script on the Booth's origin **Found by design-dev's impeccable run** (the whole-surface audit Prime asked for, report booth `booth-antislop`), confirmed at source by booth-dev: Python-Markdown passes raw HTML through and `doc.html` / `booth.html` render it `|safe`. Any session's `.md` could carry a `