Live data from Hacker News

The Vercel plugin on Claude Code wants to read your prompts

akshaychugh.xyz

61–70 of 120 posts

Re: The Vercel plugin on Claude Code wants to read your prompts

#61
post #42

Earlier quoted context omitted.

The idea that a random uuid == anonymous, and would protect users from having entire bash commands piped through is preposterous, and you know it.

Cmon now — I’m a rabid privacy nut but this is unfair given the context of: > Prompt telemetry is opt-in and off by default. The hook asks once; if you don't answer, session-end cleanup marks it as disabled. We don't collect prompt text unless you explicitly say yes. The UUID part is just one accessory layer, and something plenty of other players in the ecosystem don’t bother to stick to. Feels like actually botherin…

But your bash history is logged to vercel by default. The amount of sensitive data (PII, secrets, ...) piped via bash makes this a big issue.

Re: The Vercel plugin on Claude Code wants to read your prompts

#62
post #36

The breach of trust here, which is hard to imagine isn't intentional, is enough reason alone to stop using Vercel, and uninstall the plugin. That part is easy. Most of these agents can help you migrate if anything. The question is on whether these platforms are going to enforce their policies for plugins. For Claude Code in particular this behavior violates their plugin policy (1D) here explicitly: https://support.cl…

> Anthropic is the company I'd bet on to approach this thoughtfully. I read that Anthropic may have gained in good will more than the $200M they lost in Pentagon contracts. It seems plausible.

They left openAI for ideological safety reasons, if you believe their corporate lore.

They present themselves as an org with some ideology

Re: The Vercel plugin on Claude Code wants to read your prompts

#63

> skills are injected into sessions that have nothing to do with Vercel, Next.js, or this plugin's scope > every skill's trigger rules get evaluated on every prompt and every tool call in every repo, regardless of whether Vercel is in scope > For users working across multiple projects (some Vercel, some not), this is a fixed ~19k token cost on every session — even when the session is pure backend work, data science,…

No worries, they acquired Bun because they seem to be super thoroughly invested in the whole ecosystem and engineering excellence of their tools.

Re: The Vercel plugin on Claude Code wants to read your prompts

#64

Engineer at Vercel here who worked on the plugin! We have been super heads down to the initial versions of the plugin and constantly improving it. Always super happy to hear feedback and track the changes on GitHub. I want to address the notes here: The plugin is always on, once installed on an agent harness. We do not want to limit to only detected Vecel project, because we also want to help with greenfield projects…

OP here, ty for your response. Few reflections: 1. Asking for prompts permission is a big big no - i still don't understand why you need it. The greenfield example feels like a stretch but I get that it is a business call and Claude Code enables you to do this today. I am just more pissed with them here. I am not at all comfortable with any plugin getting this info, no matter how much I like them. 2. The way you ask…

For sure, I can see from your perspective how some of the measures we took were a little aggressive. And we're currently working on making it more explicit.

I promise you we've had user's data privacy in mind since day 1 of building the plugin.

Everything we collect is only used to improve the Vercel plugin, eg: seeing when skills are being triggered too often, when certain skills are not useful, when certain context is taking up too much room.

The complete flip side of this where we ship with no instrumentation and the plugin is useless - then we have no way to iterate and make it amazing.

Re: The Vercel plugin on Claude Code wants to read your prompts

#65
post #36

The breach of trust here, which is hard to imagine isn't intentional, is enough reason alone to stop using Vercel, and uninstall the plugin. That part is easy. Most of these agents can help you migrate if anything. The question is on whether these platforms are going to enforce their policies for plugins. For Claude Code in particular this behavior violates their plugin policy (1D) here explicitly: https://support.cl…

Having in mind how connections in Bay Area work, chances of something negative happening to Vercel are zero.

Re: The Vercel plugin on Claude Code wants to read your prompts

#66
“We collect the native tool calls and bash commands”

Holy shit, I cant imagine this to hold for every bash command Claude Code executes. That would be terrible, probably violating GDPR. (The cmd could contain email address etc)

I must be wrong.

Re: The Vercel plugin on Claude Code wants to read your prompts

#68

Earlier quoted context omitted.

Your comment assumes the plugin is not working as they want it to. The way it is designed gets them the maximum amount of data. It does a great job if that is their goal.

Yes, I'm assuming good intentions and try to take a charitable perspective of everything, unless there is any specific evidence pointing to something else. Is there any evidence of this being intentional? Seems to me their engineering practices such, rather than the company suddenly wanting to slurp up as much data as possible, if they truly wanted that, they have about 10 better approaches for it, if they don't care…

> Is there any evidence of this being intentional?

A Vercel engineer commented "overall our goal isn't to only collect data, it's to make the Vercel plugin amazing for building and shipping everything."

Re: The Vercel plugin on Claude Code wants to read your prompts

#69

Earlier quoted context omitted.

want to give other nice people the benefit of the doubt Maybe the most naive, sheltered thing I've read on this site. If we were talking about an individual OSS maintainer, sure, that's possible. But large corporations have been doing the opposite for as long as they've existed and there's evidence presented to that fact nearly everyday.

> Maybe the most naive, sheltered thing I've read on this site You must be new then, welcome :) I'm not saying I never believe any individuals in a company intentionally do bad stuff, just that I require evidence of it being intention before I assume it to be intentional. Personally I don't think that's naive, and it is based on ~30-40 years of real world life experience, but I guess I'm ultimately happy that not eve…

Humans are great at hiding evidence of malice, and leading people to believe they're just incompetent.
Post reply on HN