This draws to mind the dialog that opens when you open a new project in Cursor (and VSCode too, I think), where the IDE asks the user if they trust the project they're opening. Is Cursor under the impression that this is sufficient security apparatus?
Cursor, being based on VSCode, does have the Workspace Trust feature. They ship it disabled. https://cursor.com/docs/agent/security#workspace-trust
> For untrusted repos, use a basic text editor instead.
Is that really our options here? How shitty.