As a moderately sophisticated user, I wouldn't have expected the function RemoveExtraSpaces to immediately enable a RCE attack. It sounds pretty innocuous.
It's like saying that any program running on my computer could exploit a remote code execution bug... I mean, yes, it could. But why would it, when it already has local execution rights?
The installation of an add-on shouldn’t inherently give it free reign, with the only possible defense being trust & source-code review.
It's just a game, so they don't take it very seriously, I guess. They could just revert transaction using their moderator powers if something bad happens.
This works with API functions also, which is why this works.