Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.
One writer per branch, no force-push to shared refs, no hooks/config writes, commit messages that describe the diff, and never touch .git/ — the Cursor CVE proved why.
Trunk-based + short-lived branches + feature flags beats long-running agent branches: rebase daily, one writer per module, CI on every push. Long-lived agent branches rot at model-speed — merge small, merge often.