OK I'd love to know more about how they implemented this: https://cursor.com/changelog/1-7#sandboxed-terminals
"Commands now execute in a secure, sandboxed environment. If you’re on allowlist mode, non-allowlisted commands will automatically run in a sandbox with read/write access to your workspace and no internet access."