It's far from a blindspot. People have been yelling about this from the rooftops for the last several years.
No one cares about security. People used to care for a fairly short period of time after something bad happened to them, but even that seems to have gone by the wayside as breaches, leaks, and use of exploited code has become normalized.
It's always been a discussion in packaging, around build/install/configure time, think like setup.py, Debian's postinst, etc.
The rise of editors that will own your system just by browsing to the wrong folder without opening or running anything is relatively speaking newer, but I think most people in HN audience should be able to intuit some of the risks, especially when untrusted PRs and semi-trusted LLM bots are in the mix with your "trusted" codebase.