I use PHP's eval() for an interactive testing environment on a live smallish server. It's like open-heart surgery, so I agree it's not innocuous. Of course I took care to protect the access. This environment is useful for some quick hacks and tests. If this were a bigger deployment with more at stake, I would remove this environment from the production systems. Because, you know, it's not innocuous.
Unless the language supports first class environments, and you're binding to that. (Like Common LISP, Scheme, Lua, ...)
This isn't a useful answer for you at all, but I thought I'd mention that there are "kind of" innocuous eval()'s such as Angular's eval() [1] where instead of JS being evaluated (which can lead to nasty things), an Angular expression is evaluated, which is a bit safer.
Obviously what I've just said doesn't help solve any problems here, but thought I'd throw it in there anyway :)