Allowing this is a potential security hole, since it allows the user to specify parameters like 'local-nar-cache'.