Security Risks and Mitigation for Cursor and Windsurf AI Coding Tools

Security Risks and Mitigation for Cursor and Windsurf AI Coding Tools

Trelis Research via YouTube Direct link

0:00 Is my data at risk using Cursor or Windsurf?

1 of 14

1 of 14

0:00 Is my data at risk using Cursor or Windsurf?

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Security Risks and Mitigation for Cursor and Windsurf AI Coding Tools

Automatically move to the next video in the Classroom when playback concludes

  1. 1 0:00 Is my data at risk using Cursor or Windsurf?
  2. 2 1:34 Leakage of environment variables passwords due to .cursorignore failing
  3. 3 2:30 Two ways data can be transferred to Cursor or Windsurf
  4. 4 3:07 Using .cursorignore in Cursor
  5. 5 5:58 Cursor and Windsurf have broad access to your files no sandboxing
  6. 6 7:31 .codeiumignore is more robust than .cursorignore for blocking data leakage
  7. 7 9:64 Data risks posed by automated tool calls / agents
  8. 8 10:55 Malicious instructions found while web searching or in code bases
  9. 9 11:56 Cursor Security Docs: .cursorignore is only on a “best effort” basis
  10. 10 13:45 Enabling Privacy mode and Workspace Trust on Cursor
  11. 11 14:53 Disabling snippet telemetry formerly zero-data? on Windsurf workspace trust is the same approach as for cursor
  12. 12 15:40 Security recommendations for developers and organisations using agents
  13. 13 16:39 Security suggestions for Cursor and Windsurf
  14. 14 17:43 Resources

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.