It's a reverse engineering tool. The community is going to have plenty of ability to do network analysis on it. Also, it's trivial to sandbox it, even if it weren't going to be open-sourced.
It depends how paranoid the security person you're trying to appease is, honestly. There are definitely better options, but that one will always "sound secure".
I am familiar with the concept. However, I would recommend hesitating to anyone who thinks any software from the organization, open source or no, is entirely harmless to the user...