As someone who is on the other side, the amount of familiar, LLM generated reports are overwhelming and usually falls under "not familiar with product design/security scope" category. But there are also really good ones - so I can't afford to not take actual look at each, but it gets tiring and we need a solution. Spamming the former category with LLM generated "rationale" isn't that solution (yes I can tell this art…
Opening a freshly cloned repo in Cursor shouldn’t automatically execute a binary within that repo.
Edit: yes I get that there's a trust system, but I know a lot of people just trust everything in a directory.