/**
 * Sanitize a figma-exported SVG before it touches disk (design spec §5).
 *
 * Threat model: figma-SHAPED exports, hardened against the cheap adversarial
 * variants (nesting, unquoted attrs, scheme smuggling). This is a lexical
 * pass, not a general-purpose HTML sanitizer — content from arbitrary
 * untrusted sources should go through a real sanitizer (DOMPurify) instead.
 * Strips:
 *  - <script> elements (with content) and <style> blocks (@import exfil)
 *  - <foreignObject> subtrees (arbitrary embedded HTML)
 *  - on* event-handler attributes (quoted and unquoted)
 *  - href/xlink:href values unless local fragment (#id) or data:image/
 *
 * Keeps local fragment refs (#id) and data:image embeds, which figma uses
 * for clip paths and embedded rasters.
 */
export declare function sanitizeSvg(svg: string): string;
//# sourceMappingURL=sanitizeSvg.d.ts.map