ignoring the TOS angle
unsafe code is likely being used as in unsafe rust, which is different from exploit code
certainly the wording seems to leave the door open for potentially compromised code as in supply-chain attack credential stealer or prompt injection data exfiltration, but sprites are not marketed as sandboxes for malware detonation