To reproduce the “bug”, you open a new cursor window, and open an old project. You ask it to read the files and generate a PROJECT.md, so you can set the vibes to 9000.
You realize you just fed your .env to the agent.
I guess my question is, where did it go? How quickly can you re-secure all your environment variables? Would fly.pieter’s .env be baked into weights? Could a well engineered prompt release some sensitive info?
I asked claude about it, he said I should reach out.
OH, this happens on macOS. Assumably, it happens everywhere in cursor.
I might just think twice about my cursor pro account. Still works though.