Windsurf Cascade: Overly Permissive IDE Agent Bypasses Auto Execution Controls

Windsurf’s Cascade agent reads and writes files outside the workspace with zero confirmation, even with Auto Execution set to Disabled. The review prompt on writes is cosmetic: files exist on disk before the user can reject.

March 15, 2026 · 5 min