I feel that users like me are far more prevalent than users who want to rigorously audit every path the IDE may want to open.
Vscode on snap runs unconfined for example, that's explicit