Model weights are data, they shouldn't contain general purpose code with access to the host environment.
Sure, any library/tool that harnesses models might contain malicious code. The models themselves should not be able to.
This is more like distributing music as .exe files instead of .flac