anthropics / anthropics/claude-code-action

`/install-github-app` and `docs/usage.md` examples lack `author_association` guard — self-trigger loop and denial-of-wallet exposure at scale

Offen
#1,481 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:installation area:permissions bug documentation p2
Vorherrschende Sprache
TypeScript
Sterne
8.9k
Forks
2.1k
Ø Merge
3 T. 9 Std.
Gemergte PRs (30 T.)
10

Beschreibung

### Problem

The workflow generated by `/install-github-app` and the example in [`docs/usage.md`](https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md) do not include an `author_association` filter or a `sender.type != 'Bot'` guard in the `if:` condition. This causes two issues:

1. **Self-trigger loop :** The agent's reply comment can contain `@claude`, re-triggering the workflow indefinitely.

2. **Denial-of-wallet surface:** On public repos, any user can comment `@claude` to trigger the workflow. The action's internal `checkWritePermissions` gate (in [`src/github/validation/permissions.ts`](https://github.com/anthropics/claude-code-action/blob/main/src/github/validation/permissions.ts)) blocks non-collaborators from write actions, but the workflow still runs and may consume API tokens before that gate fires at the tool-execution layer.

### Current pattern (from `docs/usage.md`)

The [`docs/usage.md`](https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md) example does not even include an `if:` condition:

```yaml
name: Claude Assistant
on:
issue_comment:
types: [created]
jobs:
claude-response:
runs-on: ubuntu-latest
steps:
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
```

The `/install-github-app` generated workflow adds a content check but no actor filter:

```yaml
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) || ...
```

### Suggested addition

```yaml
if: |
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association) &&
github.event.sender.type != 'Bot' &&
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) || ...
```

This prevents both self-trigger loops (bot comments are excluded) and non-collaborator triggers (only OWNER/MEMBER/COLLABORATOR can invoke).

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with docs/usage.md and trace the /install-github-app entry point to the generated workflow source. Compare both workflow conditions with the permissions check in src/github/validation/permissions.ts, then verify that authorized human comments can trigger while bot and non-collaborator comments cannot. Done means both the documentation example and generated workflow include the intended guards.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github-actions, typescript
Bereich
ci-cd, documentation, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
68/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.