It is more of a matter of breaking a general principle, which is don't mix executable stuff (expressions) with non-executable stuff (strings) implicitly. This has been a frequent cause of various security issues in the past eg: Sql injection, xss, various remote code execution vulnerabilities.
Strings should be dumb and without any ambiguity. On top of breaking this general principle of not mixing data and code, this pep also want to introduce numerous rules regarding various edge cases, which further makes it harder to reason about it, which increases the chances of slipping a vulnerability. For example, right now, you see a long string, you only need to look at the argument list to see what possible things it can do. Because the string itself is dumb, it cannot lie, and whatever execution that is required to produce that string, happens in the context of code itself. With this pep, this changes. Now a string is not dumb. It is smart. It can do 'stuff' on its own. It can 'hide' things, it can lie and masquerade as something innocent. I think this is bad.
Take an example of PHP. You can embedd php code in what ever content. In fact you can embedd php code in a valid image file in the metadata fields, and pass it as an Image. if you can call the image file as a script, then the embedded php code will execute to do your bidding. This has to be one of the most commonly used technique to hack sites running php. Here is one from last day [1].
Those are some of my reasons for the concerns..I know I am not still giving anything specific. But if we could easily think specific cases about how something could be exploited, we wouldn't be implementing that in the first place. So sometimes we must rely on general principles learned from the past while assessing the issues associated with something. Hence my concerns.
[1] https://www.reddit.com/r/PHP/comments/3gq3mh/my_site_was_hac...