The Vercel Plugin on Claude Code wants to read all your prompts

This is why we need better architectures like Safebox. With AI becoming more and more pervasive, and lots of holes being identified, we need to start over with a greenfield, common environment that’s locked down by default.

To quote the article:

Each of these problems has a Vercel layer and a Claude Code architecture layer. Vercel made choices I think are not okay. But the plugin architecture enabled those choices - no visual attribution, no hook permissions, no project scoping.