Cursor's default-on sandbox was the right call. When the 2.x line put the agent's terminal commands inside a locked box — refusing writes outside the project unless the user opts in — that was the security posture every AI code editor should ship. Two flaws in that wall, named DuneSlide by researchers at Cato AI Labs, prove it isn't permanent....
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3610980