Whether you can trust your users isn't an issue. Whether you can trust anyone who might come across your UI anytime in the future is an issue.
Out of general paranoia our CGI wrapper drops any characters that are not in {A-Za-z0-9-\/.@,: }. (And ':' was a recent addition, to support entering URLs.)