Hacker News new | ask | show | jobs
by hughw 13 days ago
> If the software can execute arbitrary code/binary, and you place a malicious binary, that's up to you to secure/sandbox the workspace, not the software.

What do you think PATH variables are for? Cursor just immediately adds the repo to your PATH, iiuc, without user approval.