Yes, there's no security bug here of any kind. The "novel attack surface" already assumes the attacker can execute code as your user.