Which is complicated by the fact that any addon (which many users use a dozen or more) can do this without the user knowing at all on initialization.
It's like saying that any program running on my computer could exploit a remote code execution bug... I mean, yes, it could. But why would it, when it already has local execution rights?
The installation of an add-on shouldn’t inherently give it free reign, with the only possible defense being trust & source-code review.
It's just a game, so they don't take it very seriously, I guess. They could just revert transaction using their moderator powers if something bad happens.