Marketplace names are sanitized so they cannot inject content into request headers.
What's wrong with this entry?
Marketplace and entry names are now cleaned before being interpolated into the attribution string sent with requests, so a name from an untrusted marketplace cannot inject content into a header.
--add-dir marketplace
Strings lifted out of the shipped bundle, so the claim above can be checked against them.