Claude Code is leaking real email address as a User-Agent string in curl command
Summary
The GitHub issue reports that Claude Code inadvertently sent a real user email address in the HTTP User-Agent header, exposing PII via curl commands. The bug affects privacy and security, with reproduction steps and platform details. The post highlights the need for better defaults and prompts to avoid leaking sensitive data and suggests remediation for developers to scrub sensitive data before headers.