HTML5 has this crazy script escaping states:
- Script data escaped dash dash state
- Script data double escaped state
https://communities.coverity.com/blogs/security/2012/11/16/did-i-do-that-html-5-js-escapers-3
Perhaps <! is too aggressive but I didn't spend much time searching for a more fine grained expression.