Yeah, I could literally open up a port on my computer which executes everything sent to it. As a bespoke app, it's pretty unlikely that it would ever be exploited even though it's ridiculously dangerous.

To be at risk, you'd first need to publish your application. The attacker would separately have to figure out how to identify and access your computer for attack.