anthropics / anthropics/claude-code-action

MCP comment tool escapes ! in HTML comments, making markers visible

Abierto
#971 1 comentario 0 reacciones 0 asignados Ver en GitHub
bug mcp p3
Lenguaje dominante
TypeScript
Estrellas
8.9k
Forks
2.1k
Merge medio
3 d 9 h
PR fusionados (30 d)
10

Descripción

## Bug

When using `mcp__github_comment__update_claude_comment` to post a comment containing an HTML comment marker like ``, the `!` character gets escaped to `\!`, resulting in `<\!-- claude-code-review -->` being stored in the comment body.

Since `<\!--` is not valid HTML comment syntax, GitHub renders it as visible text instead of hiding it.

## Reproduction

1. Configure a workflow that uses `claude-code-action` with a prompt instructing Claude to include `` in a comment body via `mcp__github_comment__update_claude_comment`
2. Trigger the workflow
3. Observe the posted comment contains `<\!-- some-marker -->` (with `\!`)

## Expected behavior

The HTML comment `` should be posted verbatim, so GitHub hides it as intended.

## Actual behavior

The `!` is escaped to `\!`, producing `<\!-- some-marker -->` which renders as visible text.

## Root cause

This is likely bash history expansion escaping the `!` character when the comment body passes through a shell context with double quotes. In bash, `!` triggers history expansion inside double-quoted strings and gets escaped to `\!`.

## Example

- PR: https://github.com/shellhub-io/shellhub/pull/5868
- Comment with the issue: https://github.com/shellhub-io/shellhub/pull/5868#issuecomment-3950939724

## Environment

- `anthropics/claude-code-action@v1`
- `--model claude-opus-4-6`
- Using `track_progress` and `mcp__github_comment__update_claude_comment`

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.