You should never assume any method of executing any attacker controlled code is safe, unless something explicitly calls that out and also has put Google-level amounts of effort into supporting that.
The problem isn’t the execution, it’s the scope of what it means to “execute”.