This is non-sense FUD… you don’t just execute anything you download from random relays. First you hash the data and check if it matches the note hash you requested.
From one of my previous posts:
“If you’re sending a note hash of a missing note to an unknown relay and the relay replies with anything but the note corresponding to the hash, then discard the data and disconnect.”