Runtime environments offer a flexible way to customize Automation Account Runbooks with specific packages. While base system-generated environments can’t be directly modified, they can be indirectly changed by adding packages to the old experience and then switching to the new Runtime Environments feature. It could potentially be exploited by attackers who create new runtime environments with malicious packages and assign them to target runbooks.
Source: GBHackers