Otherwise, you're already vulnerable: Anthropic can silently record every change Claude makes to every codebase, maybe they already do.
But injecting information into outputs is a little different than Claude keeping tabs internally. The point is that we do not know what information is being shipped with the fingerprint itself.