You *can* use eval... if you also use Safe and even opcode to restrict the operations they can perform. In particular, I'd get rid of all system calls and eval() within the sandbox.
For what it's worth, I'm doing a bit of research into the same thing.