This explanation leads one to believe it's used for delayed evaluation, not preventing a remote mSL injection.
This description is intentional as it can be used in both contexts.
I'll look into it's probably something local... but certainly odd.
That looks fine. This identifier was designed and implemented with the input of scripters who regularly used $safe() but wanted a core internal identifier that behaved in exactly the same way.