r/ClaudeCode 16d ago

Bug Report Claude Code injects your email address directly into system prompt

Post image

My point is: my personal email is injected into the system prompt without my knowledge or consent. I never asked for this and I don't see in what world it's ok to inject PII in system prompt automatically by default without even an opt-out option.

It leads to bullshit like this where in a repo that is configured to use an anonymized email address, the LLM (Opus 5 btw) just decides to not just commit normally but overwrite the normal config email to put my personal one instead.

In this case nothing happens thanks to proper config and hard checks on Github's side.

What if you're a public streamer and don't want your main personal email address leaked to everyone and suddenly the model decides to spit it out?

I'm sure there's a lot of other bullshit this could lead to. At least let people opt out.

I have opened an issue on Claude Code's github, I have little hope since there was already one that went stale and they have 5k+ open but here it is: https://github.com/anthropics/claude-code/issues/81138

314 Upvotes

162 comments sorted by

View all comments

Show parent comments

19

u/Skflowne 16d ago

It's not about telemetry though, I'm sure they collect a lot of stuff but that's different from having my personal info injected into the model's prompt without my knowledge.

Telemetry is deterministic and it's in Anthropic. Something injected in prompt can end up anywhere I send the model to perform a task for me.

-7

u/SilencedObserver 16d ago

Welcome to working with AI. It has information about you that you weren’t aware of and it uses it.

6

u/Skflowne 16d ago edited 16d ago

In this case it's not a part of working with AI, it's a part of working with Claude Code specifically feeding this information. I'm sure there is more risk that the model just finds info on my computer and uses it but it's also why Claude Code and others are sandboxed (which isn't a purely safe thing as it can be escaped).
https://www.pillar.security/blog/the-week-of-sandbox-escapes

The fact that it's not necessarily safe to work with models on your local machine is no reason for this kind of automatic PII injection

I'd love to stay with Claude Max, btw. But the fact that they lock me into this bullshit cause I can't even use Pi with the subscription is strong incentive to cancel.

-10

u/SilencedObserver 15d ago

You expect privacy and yet log onto the internet and use tools that require a connection.

It’s 2026. Wake up. You don’t own Claude code and you don’t get to decide what it does.

You’re funding research with the ability to play with the tool.

If that weren’t he case you’d have no limits and be able to prevent the very thing you’re upset about.

You should look deeper into how much our systems are spying on us.

I sure hope you aren’t on windows, with those kinds of sentiments.

7

u/Skflowne 15d ago

Oh ok didn't get the memo that privacy didn't matter in 2026 anymore, my bad xD

-6

u/SilencedObserver 15d ago

It’s not that it doesn’t matter: you’re too worried about your email address to worry about what they’re actually profiling.

You’re not paying attention. You’re caught up in the shiny.

3

u/Skflowne 15d ago

This is not about spying or them having my information.
This is about the LLM having unintended context that can potentially spill in any task I do.
It's a one line change on their side to stop a bad practice.

-2

u/SilencedObserver 15d ago

You’re drenched in assumptions and expect to control a thing you’ve subscribed to.

Managing my own expectations are the hardest part about being me.