Post

@edwin 🌵📈
@edwin 🌵📈@edwin·
1/9 The most interesting thing about the Claude Code leak for devtool companies: Anthropic hardcoded 120+ vendor names across 7 different systems in the source. Anthropic explicitly included your tool name in the code (or they didn’t 🤷🏻‍♂️) Thread 👇
@edwin 🌵📈 tweet media
English
2
1
2
440
@edwin 🌵📈
@edwin 🌵📈@edwin·
2/9 (MCP UI Allowlist) 37 MCP servers get first-class UI treatment. Their search + read operations collapse into clean one-liners. Everyone else dumps raw JSON. @github leads with 56 classified tools. Others include @Grafana (38), @datadoghq (30), @asana (29), @pagerduty (28), @sentry (18), @supabase (15), @todoist (16), @playwrightweb (13), @exaailabs (9), @firecrawl, @tavilyai (5). Every name is explicitly listed in a Set inside classifyForCollapse.ts.
@edwin 🌵📈 tweet media
English
1
0
0
113
@edwin 🌵📈
@edwin 🌵📈@edwin·
3/9 (Hosted Proxy) 6 vendors don’t just get UI polish. They run on Anthropic’s own infrastructure via mcp-proxy.anthropic.com: @slackhq, Gmail, Google Calendar, Google Drive, BigQuery, @pubmed. Users click “Connect” in claude.ai settings. Everyone else follows the 8-step README.
@edwin 🌵📈 tweet media
English
1
0
0
83
@edwin 🌵📈
@edwin 🌵📈@edwin·
6/9 (Secret Scanner) 36 credential patterns across 23 vendor families are blocked from entering team memory. @gitlab, @slackhq, @stripe, @shopify, @openai, @railway, @render, @buildkite GitHub alone has 5 specific rules (PAT, fine-grained PAT, app token, OAuth, refresh token). A safety feature, but missing coverage means no vendor-specific protection.
@edwin 🌵📈 tweet media
English
1
0
0
66
@edwin 🌵📈
@edwin 🌵📈@edwin·
8/9 (Plugin Tips) @vercel is the only third-party vendor with a proactive plugin install tip. When Claude Code detects vercel.json or the Vercel CLI, it suggests: /plugin install vercel@claude-plugins-official No MCP collapsing, but a different distribution channel: your tool is recommended before the developer even starts.
English
1
0
0
69
I-share