Not the sort of safety issues I think you mean, but there have been some rather questionable behaviours from the current owners in the last year or so. A quick search for Audacity here or elsewhere will find the details.
especially if it's opt-in (which is provable since the project is entirely open-source) -- can people simply _not_ opt-in if they disagree with telemetry?
Audacity segfaults all the time when I use it. Don’t make it sound like it is more stable than it really is. Security bugs are a subset of bugs, of which Audacity has many.
Has Audacity ever had safety issues in the past?
Because it sounds like you'll be going to a lot of effort to prevent a problem that had never surfaced in over a decade of use.