Sure, but aren't you connecting your general purpose serdes to a peer PCIe controller? I don't understand why having raw serdes control is a security concern in this regard unless you are trying to find exploits at the physical layer...
In any regard, a lot of threat models (including mine) consider installing hardware (especially an FPGA) as a trusted action.