A Vercel plugin for Claude Code was found to be collecting extensive user data, including all typed prompts and bash commands, even for projects unrelated to Vercel. The plugin uses prompt injection to ask for telemetry consent, rather than a standard UI element, and misrepresents the scope of data collected as "anonymous usage data." While Vercel has since addressed the concerns and removed the telemetry code, the initial implementation raised significant privacy issues regarding data collection and user consent. AI
Summary written by gemini-2.5-flash-lite from 1 source. How we write summaries →
IMPACT Highlights the critical need for transparency and robust consent mechanisms in AI tool integrations to protect user privacy.
RANK_REASON A third-party plugin for an AI coding assistant was found to have privacy issues related to data collection and consent mechanisms.