Unfortunately it can't help people that happen to create new projects right when the vulnerability is up, since they rarely configure that in their home folder. And making it a default could impair security fixes (for instance the Next.js/React CVEs).