This is why we need better architectures like Safebox. With AI becoming more and more pervasive, and lots of holes being identified, we need to start over with a greenfield, common environment that’s locked down by default.
To quote the article:
Each of these problems has a Vercel layer and a Claude Code architecture layer. Vercel made choices I think are not okay. But the plugin architecture enabled those choices - no visual attribution, no hook permissions, no project scoping.