🛠️ Managing Custom HTML Content with OTTO Agent

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

Use OTTO Agent to create, edit, validate, and preview custom HTML content directly in Search Atlas. Built-in markup validation catches errors before deployment and flags common security risks such as embedded scripts and event-handler attributes.

📋 What Custom HTML Support in OTTO Agent Does

The Custom HTML feature in OTTO Agent lets you manage HTML content blocks without switching to a separate CMS or code editor. You can:

  • Create new HTML blocks and assign them to pages OTTO Agent manages.
  • Edit existing HTML content directly in the OTTO Agent interface.
  • Validate markup against Search Atlas HTML rules — which flag common security risks such as embedded <script> tags and on* event-handler attributes — before saving.
  • Preview the rendered output before deploying to your live site.

This workflow applies to content OTTO Agent manages directly — it is separate from your CMS integration.

🚀 How to Create a Custom HTML Block in OTTO Agent

  1. In Search Atlas, open OTTO Agent from the left navigation.
  2. Select the site you want to work on.
  3. Go to the Content tab and click Add Custom HTML.
  4. Enter a Label to identify this HTML block.
  5. Type or paste your HTML into the editor panel.
  6. Click Validate to check your markup. Any errors appear inline with a plain-English description.
  7. Once validation passes, click Preview to confirm the rendered output looks correct.
  8. Click Save to store the block. OTTO Agent queues the block for deployment on the next sync cycle (typically within a few minutes). You can monitor deployment status in the OTTO Activity log.

A green Saved confirmation banner appears when the block is stored successfully.

✏️ How to Edit an Existing Custom HTML Block in OTTO Agent

  1. In Search Atlas, open OTTO Agent from the left navigation.
  2. Select the site that contains the block you want to update.
  3. Go to the Content tab.
  4. Locate the HTML block by its Label in the list of saved blocks.
  5. Click the block row or the Edit icon next to it to open the editor panel.
  6. Modify your HTML in the editor panel.
  7. Click Validate to confirm the updated markup passes all rules.
  8. Click Preview to review the rendered output.
  9. Click Save to apply your changes. OTTO Agent queues the updated block for deployment on the next sync cycle.

OTTO Agent preserves previous versions each time you save, so earlier states remain accessible for reference.

✅ HTML Validation Rules in OTTO Agent

OTTO Agent validates your HTML before allowing a save. The validator checks for:

  • Well-formed markup — all tags must be properly opened and closed.
  • Supported HTML5 elements — non-standard or deprecated elements are flagged.
  • No inline event handlers — attributes such as onclick, onload, and onerror are blocked.
  • No restricted resource tags — <script>, unauthorized <link>, and <iframe> elements are not permitted.

When validation fails, the editor highlights the problem line and describes the issue. Fix the flagged line and click Validate again. The Save button remains disabled until every error is resolved.

👁️ How to Preview Custom HTML in OTTO Agent

  1. With your HTML block open in the editor, click Preview.
  2. A preview panel renders your HTML as it will appear on the page.
  3. Review layout, text, links, and structure in the preview panel.
  4. Close the preview panel to return to the editor and make further changes if needed.

The preview renders your HTML block in isolation. Global site styles and fonts may look different from the live page — this is expected behavior and does not affect the deployed output.

⚠️ Script Injection Prevention and Blocked HTML Patterns

OTTO Agent automatically blocks HTML patterns that introduce security risks. The following are flagged or stripped at validation:

  • <script> tags — all script blocks are rejected and will never be saved or deployed.
  • <iframe> embeds — inline frames loading external URLs are not permitted.
  • JavaScript protocol links — href="javascript:…" values are removed.
  • Inline event handler attributes — any on* attribute (e.g., onclick, onmouseover, onerror) is blocked.

These rules run automatically on every validation. If a blocked pattern is detected, the validator flags the relevant line with a clear error message. Remove or replace the flagged element and click Validate again. No blocked content can reach your live site through OTTO Agent.

🔧 Known Issues and Recent Fixes

Double HTML encoding on injected content — resolved. A previous bug caused OTTO injection to double-encode special characters, so symbols like & rendered as &amp; and ' rendered as &#39; on the live site.

If your site previously displayed literal strings like &amp; or &#39; after enabling OTTO, this encoding bug has been resolved. Review any HTML blocks created before the fix and re-save them to trigger a clean render.

🎯 You can now create, validate, preview, and deploy custom HTML blocks through OTTO Agent safely and efficiently. To learn how OTTO Agent manages other on-page content types, see OTTO Agent Content Management Overview.