> Also it is possible that while building malicious application user will embed > content of his own /etc/shadow or any other private information into binary.
So sandbox your build environment, it's the only thing that has a chance of working. Everything else is like cleaning your teeth with a broom, it hurts and yet doesn't accomplish anything.
