If check, GROOVY token macro processing via Token Macro Plugin is allowed. The evaluation of macro is done in System Groovy, therefore any user can run arbitrary system script, regardless he has administer permission!