This doesn't support development containers (https://containers.dev), which means I can't insulate my machine from AI tooling. Not keen on this unless it's somehow earth-shattering.

why doesn't it support them?

The remote containers extension on VSCode is proprietary. Cursor had to write their remote extension suite.