That could be an issue with being allowed to redistribute mods, also someone uploading something who doesn't have the rights to do so. Automatic scans for not yet known things are useless. Being able to disable automatic downloads is a necessity if someone actually wants to do something like that. Scripts shouldn't be able to access the disk directly, but given the possible number of exploitable bugs in the code that executes them (which is partly due to no thought being given to doing that with untrusted code (and running untrusted code is not something one should really do anyway)) and the used libraries.