Is it? I've read the article twice (yesterday when you posted it and last year when it was first published), and that was not my interpretation.
It's right there in the article, not sure what to say.
> Unlike Tramp, which lives off the land on the remote connection, VSCode mounts a full-scale invasion: it runs a Bash snippet stager that downloads an agent, including a binary installation of Node.
> I would be a little nervous about letting people VSCode-remote-edit stuff on dev servers, and apoplectic if that happened during an incident on something in production.