anthropics / anthropics/claude-code-action

MCP comment tool escapes ! in HTML comments, making markers visible

オープン
#971 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug mcp p3
主要言語
TypeScript
スター
8.9k
フォーク
2.1k
平均マージ
3日 9時間
マージ済み PR(30日)
10

説明

## Bug

When using `mcp__github_comment__update_claude_comment` to post a comment containing an HTML comment marker like ``, the `!` character gets escaped to `\!`, resulting in `<\!-- claude-code-review -->` being stored in the comment body.

Since `<\!--` is not valid HTML comment syntax, GitHub renders it as visible text instead of hiding it.

## Reproduction

1. Configure a workflow that uses `claude-code-action` with a prompt instructing Claude to include `` in a comment body via `mcp__github_comment__update_claude_comment`
2. Trigger the workflow
3. Observe the posted comment contains `<\!-- some-marker -->` (with `\!`)

## Expected behavior

The HTML comment `` should be posted verbatim, so GitHub hides it as intended.

## Actual behavior

The `!` is escaped to `\!`, producing `<\!-- some-marker -->` which renders as visible text.

## Root cause

This is likely bash history expansion escaping the `!` character when the comment body passes through a shell context with double quotes. In bash, `!` triggers history expansion inside double-quoted strings and gets escaped to `\!`.

## Example

- PR: https://github.com/shellhub-io/shellhub/pull/5868
- Comment with the issue: https://github.com/shellhub-io/shellhub/pull/5868#issuecomment-3950939724

## Environment

- `anthropics/claude-code-action@v1`
- `--model claude-opus-4-6`
- Using `track_progress` and `mcp__github_comment__update_claude_comment`

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。