[Python-Dev] Restricted execution: what's the threat model?