Thanks, that makes sense.

Still, for user-level systemd, that means the bus is open to any binary running with the user's credentials.

This is not any worse than the risk of running ssh-agent, though.