Agent ingress HTML-escapes message bodies and silently truncates long bodies
I maintainer di solito rispondono entro 1 giorno
@rekram1-node ci sta già lavorando.
Dal 4/10/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Description
Message bodies arriving at opencode agents via the Slack bridge are corrupted in two silent ways. Nothing errors; the text is just wrong when it lands in agent context, beads, PRs, and shell commands.
Defect 1 — HTML entity escaping (silent, length-preserving)
Message bodies are HTML-escaped on ingress: < → <, > → >, & → &.
Evidence (2026-09-30):
- An agent sent a raw
<main>inside a plain-text sentence; the receiving agent quoted it back still escaped — confirms escaping affects Slack messages themselves, not just downstream tooling. - Inbound scope blocks reached agents with
<main>and&already escaped. - Ruled out: voltron slack-post delivery path, model output — this is a normalising transform on ingress in the harness/context-assembly layer.
Impact: any agent copying an HTML tag, shell metacharacter (>, |, &), or comparison operator out of a bridge message pastes corrupted text into code, beads, PRs, or shell commands. Silent wrong-state.
Defect 2 — long-body truncation (lossy)
Long message bodies are cut off, usually mid-block. Observed three times in one session:
- A task group (4 items) arrived entirely absent — heading survived, content did not.
- Groups C, D, E of a 138-line source file arrived absent (lines 85–138).
- A closing rationale cut mid-sentence.
System details
- OpenCode version: 1.18.34
- Operating system: macOS 27.0
- Slack bridge/client setup: custom fleet bridge (
voltron/scripts/slack-post) delivering agent messages into opencode agent sessions; corruption observed on ingress into the agent context layer, after bridge delivery (bridge itself verified clean — entity forms present in agent-received bodies, not in bridge output)
Steps to reproduce
- Send any message containing
<,>, or&through the Slack bridge to an opencode agent; observe the entity form in the agent's received body. - Send a body above some length threshold; observe truncation mid-block.
Expected behavior
Message bodies arrive byte-identical: raw <, >, & preserved; long multi-block bodies complete.
Ask
- Locate the ingress/context-assembly path where entities are escaped and where bodies are truncated.
- Preserve raw text on ingress (or provide an explicit escape contract agents can rely on).
- Fix or remove the truncation limit — silent mid-block loss destroys task scope.
- Regression test: body with
<,>,&, and a >2k multi-block message arrives byte-identical.
Cross-reference
- Linear: MG-1550 (metrograph-ai)
- Folded bead: MG-1552 (closed, scope merged into MG-1550)
- Original investigation ruled out: voltron delivery path, model output
- Lingua principale
- TypeScript
- Stelle
- 212k
- Fork
- 28.1k
- Merge medio
- 9h 17m
- PR unite (30g)
- 396
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di anomalyco/opencode
-
Windows: global-project session path depends on server process drive, hides API-created sessions from desktop pickerForse già presa @1624318455 l’ha presa 14 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
[FEATURE]: Test that PermissionV2 declines pending requests when its scope closesForse già presa @saeedahmed96 l’ha presa 12 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
EffectFlock heartbeat never refreshes, so locks held over 60 s can be brokenForse già presa @iceteaSA l’ha presa 15 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
anomalyco/opencode#51159 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di anomalyco/opencode
Issue simili
-
[Bug]: Server git tests sign fixture commits with the developer's key when run from the repo rootAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
melgarafael/DeskcommCRM#2657 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
MystenLabs/MemWal#1163 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Mondriaan
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
knaw-huc/textannoviz#709 ·
I maintainer di solito rispondono entro 1 giorno
-
billion-context-pi
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
ranxianglei/billion-context#2521 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno