Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Agent ingress HTML-escapes message bodies and silently truncates long bodies

オープン
#53,224 コメント 1 件 リアクション 0 件 担当者 1 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@rekram1-node がすでに取り組んでいます。

2026年10月4日 から。

評価

この issue はまだ評価されていません。

説明

Description

Message bodies arriving at opencode agents via the Slack bridge are corrupted in two silent ways. Nothing errors; the text is just wrong when it lands in agent context, beads, PRs, and shell commands.

Defect 1 — HTML entity escaping (silent, length-preserving)

Message bodies are HTML-escaped on ingress: < → &lt;, > → &gt;, & → &amp;.

Evidence (2026-09-30):

  • An agent sent a raw <main> inside a plain-text sentence; the receiving agent quoted it back still escaped — confirms escaping affects Slack messages themselves, not just downstream tooling.
  • Inbound scope blocks reached agents with &lt;main&gt; and &amp; already escaped.
  • Ruled out: voltron slack-post delivery path, model output — this is a normalising transform on ingress in the harness/context-assembly layer.

Impact: any agent copying an HTML tag, shell metacharacter (>, |, &), or comparison operator out of a bridge message pastes corrupted text into code, beads, PRs, or shell commands. Silent wrong-state.

Defect 2 — long-body truncation (lossy)

Long message bodies are cut off, usually mid-block. Observed three times in one session:

  1. A task group (4 items) arrived entirely absent — heading survived, content did not.
  2. Groups C, D, E of a 138-line source file arrived absent (lines 85–138).
  3. A closing rationale cut mid-sentence.

System details

  • OpenCode version: 1.18.34
  • Operating system: macOS 27.0
  • Slack bridge/client setup: custom fleet bridge (voltron/scripts/slack-post) delivering agent messages into opencode agent sessions; corruption observed on ingress into the agent context layer, after bridge delivery (bridge itself verified clean — entity forms present in agent-received bodies, not in bridge output)

Steps to reproduce

  1. Send any message containing <, >, or & through the Slack bridge to an opencode agent; observe the entity form in the agent's received body.
  2. Send a body above some length threshold; observe truncation mid-block.

Expected behavior

Message bodies arrive byte-identical: raw <, >, & preserved; long multi-block bodies complete.

Ask

  1. Locate the ingress/context-assembly path where entities are escaped and where bodies are truncated.
  2. Preserve raw text on ingress (or provide an explicit escape contract agents can rely on).
  3. Fix or remove the truncation limit — silent mid-block loss destroys task scope.
  4. Regression test: body with <, >, &, and a >2k multi-block message arrives byte-identical.

Cross-reference

  • Linear: MG-1550 (metrograph-ai)
  • Folded bead: MG-1552 (closed, scope merged into MG-1550)
  • Original investigation ruled out: voltron delivery path, model output
主要言語
TypeScript
スター
212k
フォーク
28.1k
平均マージ
9時間 17分
マージ済み PR(30日)
396

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

anomalyco/opencode のほかの issue

anomalyco/opencode の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。