> Couldn't we simply agree not to execute un-audited code from unknown third parties? Seems like the same threat vector as unknown executable code delivered over email to me.
There are a couple of problems with this.
First, limiting the spread and ensuring that nobody executes the message is non-trivial (especially given that currently the protocols dictate "These recordings should be made available to the international institutions listed above and to members of the scientific community for further objective analysis and interpretation". Also, unless all instances of the message were destroyed AND transmission ceased permanently, humanity is left with a literal Pandora's Box. It's hard to imagine that this box wouldn't be opened eventually by someone with more curiosity that caution.
Second, there are messages that cannot be safely audited without running. A self-bootstrapping decompressor/compiler that modifies it's own code as it parses itself into existence could be impossible to evaluate. Committing ourselves to never executing un-audited code means accepting there are certain types of messages we would never understand.
So while your solution is a possibility, it is not an easy one and it is not one without costs. Maybe I'm not risk averse enough but I (like authors) think the potential gains of executing ET code outweigh the risks associated