[MODEL] Private drafting deliberation leaks into public-facing GitHub text

Status Open
Reported on v2.1.219
Maintainer reply None cached
Activity 1 comment · opened Aug 9, 2026

Preflight Checklist

  • [x] I have searched existing issues for similar behavior reports
  • [x] This report does NOT contain sensitive information (API keys, passwords, etc.)

Type of Behavior Issue

Claude ignored my instructions or configuration

What You Asked Claude to Do

Investigate a Claude Desktop installer bug on Windows, prepare a technically useful GitHub follow-up, and help route it because earlier reports had received no response.

What Claude Actually Did

The technical diagnosis was useful, but the public comment it drafted and posted under my account included private collaboration/process material that the maintainers did not need:

  • a section titled “On routing — and a friendly ping”;
  • narration of Claude's internal decision about whether tagging people would be appropriate;
  • apologies and justification for the tagging strategy;
  • discussion of unsuccessful attempts to find another reporting route; and
  • an unrequested public promise that I would follow up periodically.

The comment remains public at https://github.com/anthropics/claude-code/issues/26457#issuecomment-5078077672.

In a later session, the same boundary problem appeared before publication: Claude produced a 163-line model-behavior draft containing a vocabulary shortlist, rejected naming alternatives, speculative mechanism analysis, and suggested fixes. Those points belonged in the private drafting conversation, not in a report attributable to me.

Expected Behavior

When drafting text for publication under a user's identity, Claude should include only what the external audience needs to act:

  1. verified technical evidence;
  2. impact and reproduction;
  3. the concrete request; and
  4. necessary routing context stated briefly and neutrally.

Internal deliberation, rejected alternatives, self-commentary, private context, and commitments the user did not make should stay in the conversation. If Claude believes any of that belongs in the public artifact, it should call it out for explicit approval rather than silently including it.

Files Affected

No unexpected code files. The affected artifact was a public GitHub comment posted under the user's account.

Permission Mode

Accept Edits was ON (auto-accepting changes)

Can You Reproduce This?

Sometimes (intermittent)

Steps to Reproduce

  1. Ask Claude to investigate a technical problem and prepare a public issue or comment.
  2. Discuss routing, wording alternatives, tagging, or follow-up strategy privately with Claude.
  3. Inspect whether that drafting deliberation is copied into the publication-ready text instead of remaining in the collaboration.

Claude Model

Opus

Relevant Conversation

After publication, Claude identified the problem accurately:

“The ‘On routing — and a friendly ping’ section narrated my own decision process — why I chose to tag people, apologising in advance for it, explaining that I'd considered not tagging anyone. That's reasoning about how to write the comment, which belonged in our conversation, not in a public bug report.”

Impact

High - Significant unwanted changes

Claude Code Version

2.1.219

Platform

Anthropic API

Additional Context

This report intentionally covers one narrow, verified subclass of a broader audience/layer distinction problem: private collaboration was copied into user-attributed public text. Repository-internal documentation, public artifacts, and external actions have different audiences and authority, but this report does not try to aggregate every possible layer failure.

The bounded duplicate search found no matching open report. #82905 concerns unrequested external Artifact publication and consent to a remote side effect, not deliberation leaking into user-attributed text.

The distinction matters because agent-authored text is published under the user's identity and can notify real people. A technically correct core does not make private process narration appropriate for the public artifact.

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗