As long as no binaries are allowed in user directories and the current dir is not allowed in a root level users path (in fact root path can be hard coded to a known good directory set and checked regularly.) and email, web and other services do not run under privileged account... no problem with getting a root-kit.