It depends; if all you want to do is lift normal functions to the domain of unsafe operation (where an unsafe input implies unsafe output), then sure:
newtype Unsafe a = Unsafe a
instance Functor Unsafe where
fmap f (Unsafe k) = Unsafe . f $ k
addTwo :: Int -> Int
addTwo = (+2)
unsafeAddTwo :: Unsafe Int -> Unsafe Int
unsafeAddTwo = fmap addTwo
But really, I'm not sure this is the right approach. Even values generated inside my program need to be quoted for inclusion on an HTML page. What you want to avoid is double-quoting, so what you need is simpler:
data Content = Quoted String | Unquoted String
output :: [Content] -> Content
output = concatMap f
where f (Unquoted x) = quote x
f (Quoted x) = x
Now the type system ensures that (output . output) == output, which is what you really want to ensure. Tainted data, I think, is a separate concern. And the solution, in that case, doesn't involve a functor, it involves making sure your library tags everything as Unsafe and that your data validation functions remove that annotation:
type Params a = Map String (Unsafe a) -- keys may also be unsafe, YMMV
readHtmlForm :: Request -> Params String
validateField :: Validatable a => Unsafe a -> a
main = output . Unquoted . validateField . get "foo" . readHtmlForm <$> fakeHttpRequest