This seems more like a problem with poorly developed software that has no clear boundaries. With basic security measures, developers will have to out of their way and intentionally create automated hacking tools.
I develop open source software, and I am very specific on what it is able to do.
The software doesn't connect to any external dependencies expect for specific services used for authentication and data persistence.