Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes—opening a repository in some code editors can trigger project-controlled actions, but opening an ordinary folder in a file manager does not inherently run its code. The risk depends on the editor and its trust settings. Visual Studio Code (VS Code) opens a new, unfamiliar folder in Restricted Mode; Oasis Security Research reported a Cursor configuration in which a repository task could run on folder open without a trust prompt.

How can opening a code workspace trigger execution?

A repository can include editor metadata as well as source files. For example, VS Code task definitions can live in a project’s .vscode folder and run scripts or binaries. Those files are shared with people who clone the repository, so a task can become an execution path when an editor allows it to run.

The relevant risk is not that every folder runs code when opened. It is that an IDE may interpret project-controlled settings or tasks, and its defaults determine whether it asks before doing so. A file manager opening a folder is a different action from an IDE opening that folder as a code workspace.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens when you open an unfamiliar repository in VS Code?

Microsoft says that “When you open a new, unfamiliar folder, VS Code opens it in Restricted Mode to prevent automatic code execution while you review the contents.” The Restricted Mode banner or status badge indicates that state. Workspace Trust was introduced in VS Code 1.57, according to Microsoft’s May 2021 release notes.

What Restricted Mode limits

  • Tasks: Running or enumerating tasks prompts you to trust the folder first. This matters because repository task definitions can execute scripts or binaries.
  • Integrated terminal: Opening a terminal is blocked by default. Shell setup can execute code based on workspace contents.
  • Debugging and settings: Debugging is disabled pending trust, and workspace settings that could point to malicious executables are limited.
  • Extensions and AI agents: Extensions without explicit support for Workspace Trust are disabled or limited. Current documentation also says AI agents are disabled in Restricted Mode, noting that agent context can create prompt-injection exposure.

These controls reduce automatic execution while you inspect a project; they are not a complete sandbox. Microsoft warns that “Workspace Trust can’t prevent a malicious extension from executing code and ignoring Restricted Mode.” Install and run extensions only from publishers you trust. The full behavior and limitation are described in Microsoft’s Workspace Trust documentation.

#1 Best Overall

How does the reported Cursor case differ?

Oasis Security Research reported that Cursor shipped with Workspace Trust disabled by default in the configuration it examined. Its report describes a malicious repository containing .vscode/tasks.json with a task set to runOn: "folderOpen". According to Oasis, affected users on that default configuration could open the repository and have the task execute without a trust prompt. The report characterized VS Code with Workspace Trust enabled as lower risk.

This is an attributed finding about the configuration described in Oasis’s report, not an independent retest of every Cursor version or a claim that all current installations behave this way. Oasis published the report on 2025-09-10 and updated it on 2026-05-01. Its account and recommendations are in “Open Repo, Get Pwned (Cursor RCE)”.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cursor precautions suggested by Oasis

  • Enable Workspace Trust and require a startup prompt.
  • Consider setting task.allowAutomaticTasks to "off".
  • Use a viewer-only editor or a disposable container or virtual machine for repositories you do not yet trust.

Because editor behavior can change, check the current product settings and documentation before applying advice tied to a reported configuration.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does Microsoft Visual Studio use the same trust controls?

No. Microsoft Visual Studio is a separate product from Visual Studio Code, with distinct controls. Microsoft Learn says Visual Studio 2022 and later can warn when untrusted code is opened, integrate warnings based on Mark of the Web, and support configurable trust prompts and trusted locations. Mark of the Web is metadata Windows attaches to downloaded files to indicate a potentially unsafe origin. The exact behavior depends on configuration; Microsoft documents the options in Configure trust settings for files and folders.

How should you inspect an unfamiliar repository?

  1. Keep it untrusted at first. When the editor offers a restricted or untrusted state, leave it there while you review the project. Check the editor’s trust indicator instead of assuming the workspace is protected.
  2. Inspect before enabling execution paths. Look through project configuration and task definitions, including the .vscode folder where applicable. Do not run a task or launch debugging simply because the editor offers to do so.
  3. Delay the integrated terminal. Opening a terminal can invoke shell setup influenced by workspace contents. Wait until you have a reason to trust the repository.
  4. Treat prompts as security decisions. Trusting the folder, running a task, starting debugging, opening a terminal, or enabling an extension can change what the project or its tools are allowed to do.
  5. Use isolation when inspection itself is risky. For an unknown repository that you must examine, a viewer-only editor or disposable container or VM provides separation from your usual development environment. For Cursor teams, the specific safeguards above are Oasis Security Research’s recommendations for the configuration it reported.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.