[eluser]Pascal Kriete[/eluser]
If you don't want html to display, convert it to entities. Sorry if I'm being thick, but I'm just not seeing how this is harmful.
Now if you're putting this into a form, it should definitely be using form_prep to make sure you're not breaking out of the entry field.