You should treat running a code analyzer/builder/linter against a codebase as being no safer than running that codebase itself.