I read it as short for, "it makes me vulnerable to tracking and malware."
The problem isn't that bad people use it sometimes; it's that bad people can and do try to use JavaScript to harm me. This isn't a theoretical risk.
I enable it for websites I trust and I occasionally write browser-side stuff in CoffeeScript, but by default, JavaScript is blocked.