问题
使用 Cursor、Claude Code 等 agent 聊天的开发者,正在被「隐形上下文注入」困扰:Cursor 会把最近查看文件的路径注入到每次 agent 聊天的第一条消息中,包括新聊天,导致不相关文件混入上下文,且用户无法移除或在界面中看到该列表;Claude Code 的 VS Code 侧边栏会自动附加打开文件和选区,只有一个每次都会重置的眼睛图标开关——「Every single message I send requires an extra click on the eye icon to hide irrelevant context」。更深一层,用户「cannot audit what the model actually "sees" vs what they sent」,这让调试 agent 异常行为和指令遵循问题变得显著更难。核心痛点是:不相关上下文污染 + 用户对模型实际输入缺乏可见性。
目标用户
重度使用 AI 编程 agent 的开发者:Cursor 用户(agent 聊天模式)和 Claude Code 用户(尤其 VS Code 扩展、保持多个无关参考文件打开的工作流)。这是一个随 AI 编程工具普及快速增长的人群,但单点痛情程度中等(pain 3-4),付费意愿未知。
解决方案
- 发送前审计面板:在 agent 聊天发送前,列出本次将附带的全部上下文(打开文件、选区、最近查看文件、CLAUDE.md 等),并高亮「用户未主动添加却被注入」的部分
- 持久开关:提供按 workspace 的设置,一键禁止特定类型的自动附加(如默认关闭「最近查看文件」),替代每次都要点一遍的眼睛图标
- 会话上下文日志:每次请求后保存模型实际收到的完整 prompt 上下文,用户调试 agent 异常行为时可逐条 diff「我以为发了的」vs「实际发了的」
- 污染告警:检测到跨任务的不相关文件被带入新会话时给出提示
AI 的角色:本产品不生成内容,而是作为 AI agent 的「上下文透明层」——用规则和差异比对识别注入内容,帮助用户控制 AI 的实际输入质量。
为什么是现在
三条信号集中在 2026 年 2-10 月,显示 agent 聊天已成为主流编程工作流,随之暴露的「隐藏上下文注入」是新出现的问题类别:Cursor 论坛在 2026-10 出现相关 feature request,Claude Code 的两个 GitHub issue 分别拿到 215 和 258 分、41 和 83 条评论,说明随着 agent 使用时长增加,调试 agent 行为的需求正在集中爆发。
MVP 范围
做:一个 VS Code / Cursor 扩展,覆盖 Claude Code 与 Cursor 两类场景:
- 在每次发送前拦截 agent 聊天请求,展示实际附带的上下文清单(最近查看文件、当前打开文件、选区等)
- 提供持久化的自动附加开关(相当于用户要求的 autoAttachContext: false),支持按 workspace 记忆
- 发送后留一份可回看的「本次实际发给模型的完整上下文」日志,方便事后 debug
不做:
- 不做服务端注入内容(如 CLAUDE.md、system prompt 内部处理)的完整审计——技术上需要逆向协议,首版不碰
- 不做团队协作、云端同步、自定义规则引擎
风险
- 平台依赖(最大风险):Cursor 和 Claude Code 官方修复成本极低(一个持久化设置、一个上下文查看面板),官方一旦补齐,独立工具的存在意义大幅缩水;信号本身就是在官方论坛/issue 里提的功能请求
- 技术风险:Cursor 注入发生在客户端但不可见、Claude Code 服务端注入不可审计,需要跟进逆向或扩展 API 变更,产品每次上游更新都可能失效
- 合规/隐私:记录「实际发送的完整上下文」日志涉及用户代码本地留存,需默认本地存储、明确不外传
- 变现风险:目标用户是习惯免费开发者工具的人群,三条信号均无付费意愿证据
信号证据
这张卡片依据的原始讨论。摘录保持原文,点“原文”查看上下文。
Cursor 论坛 · Ideas10月1日功能请求▲ 00 条评论
“Cursor attaches a list of recently viewed file paths to the first message of every agent chat, including new chats. I start a new chat so the agent works only from what I give it, and the list puts files from earlier, unrelated work back into its context.”
Cursor 会将最近查看文件的路径注入到每次 agent 聊天的第一条消息中,包括新聊天,导致不相关文件混入上下文,且用户无法移除或在界面中看到该列表。原文
GitHub Issues · anthropics/claude-code4月12日痛点▲ 21541 条评论
“Unverifiable behavior: Users cannot audit what the model actually "sees" vs what they sent — makes debugging agent misbehavior significantly harder”
Users cannot audit what hidden server-injected content the model actually sees versus what they sent, making debugging agent misbehavior significantly harder and possibly degrading instruction adherence.原文
GitHub Issues · anthropics/claude-code2月10日投资方向▲ 25883 条评论
“Every single message I send requires an extra click on the eye icon to hide irrelevant context. Over a session with dozens of messages this adds up to significant friction.”
The VS Code sidebar chat auto-attaches the open file and selection to every prompt, with only a per-prompt eye-icon toggle that resets, no persistent setting to disable it.原文