Obviously, you need to sandbox all tools in the chain that handles untrusted data. This is security 101 stuff