It rather involved being on the other side of this airtight hatchway: If they can run code, then they can run code
Some people can't get over the initial burst of adrenaline when they think they've found a security vulnerability and rush to file a report with Microsoft so they can get credit for it and add it to their "security vulnerability portfolio" to show that they are so wicked cool. Learning that what they found isn't a security vulnerability isn't goin...