Also, document a potential shell injection in core.unpack_srcrpm (via the "files" parameter), which cannot be exploited, because "files" is not used by the current osc code. Fixes: #340 ("osc add of directories does not quote the argument")