A hardened devcontainer configuration for safely reviewing potentially malicious code in Cursor/VS Code.
- ๐ Network isolated - No outbound connections from container
- ๐ Read-only filesystem - Container can't be modified
- ๐ซ Dropped capabilities - No privilege escalation
- ๐พ Resource limits - Prevents fork bombs and memory exhaustion