I always run such tools inside sandboxes to limit the blast radius.
Compromising all code in one directory is bad. Compromising all my data in all other directories, including mounted cloud drives, is worse.
I restrict most dev tools to access only the current directory.
So, stealing credentials in the current directory and in all other directories are the same thing?