I'm not worried about package authors, I worry about the bad guys
modifying
legitimate package to run malicious code.
If I were you I'd worry more about `Local Variables:'.
Emacs-21.1 had many security holes there and although we have fixed
a few since (tho not in 21.2 and probably not in 21.3 either), I'm sure
there are many more left, all pretty easy to exploit (as long as you can
get someone to open the file you wrote).
Stefan