You started this thread to warn about the risks of running untrusted JavaScript before the appropriate mitigations are in place, yet you expect people to open a PDF from misc0110.net with no additional context?
Assuming it's safe based on available information is very bad. Even your comment isn't enough because you could be working with someone to drive people to a malicious link.