Self-hosted runners inherit local trust

A build runner you host sits inside your network with whatever access that implies.

It also runs code from your repositories, which for a public or widely contributed project means running code from people you do not know. That combination, untrusted code on a trusted network, is exactly what you would avoid anywhere else, and it is the default arrangement for self-hosted CI.

More on CI/CD security