anthropics / anthropics/claude-code-action

MCP comment tool escapes ! in HTML comments, making markers visible

Aperta
#971 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
bug mcp p3
Lingua principale
TypeScript
Stelle
8.9k
Fork
2.1k
Merge medio
3g 9h
PR unite (30g)
10

Descrizione

## Bug

When using `mcp__github_comment__update_claude_comment` to post a comment containing an HTML comment marker like ``, the `!` character gets escaped to `\!`, resulting in `<\!-- claude-code-review -->` being stored in the comment body.

Since `<\!--` is not valid HTML comment syntax, GitHub renders it as visible text instead of hiding it.

## Reproduction

1. Configure a workflow that uses `claude-code-action` with a prompt instructing Claude to include `` in a comment body via `mcp__github_comment__update_claude_comment`
2. Trigger the workflow
3. Observe the posted comment contains `<\!-- some-marker -->` (with `\!`)

## Expected behavior

The HTML comment `` should be posted verbatim, so GitHub hides it as intended.

## Actual behavior

The `!` is escaped to `\!`, producing `<\!-- some-marker -->` which renders as visible text.

## Root cause

This is likely bash history expansion escaping the `!` character when the comment body passes through a shell context with double quotes. In bash, `!` triggers history expansion inside double-quoted strings and gets escaped to `\!`.

## Example

- PR: https://github.com/shellhub-io/shellhub/pull/5868
- Comment with the issue: https://github.com/shellhub-io/shellhub/pull/5868#issuecomment-3950939724

## Environment

- `anthropics/claude-code-action@v1`
- `--model claude-opus-4-6`
- Using `track_progress` and `mcp__github_comment__update_claude_comment`

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.