You can add literally anything, and all Steam does is launch the executable you specify. And maybe take screenshots if you use the overlay.
Valve could actually look through the games people have added and do some sort of major crackdown, but for better or worse they seem to have left this alone. Still, though, I’d consider it a vulnerability, and I also recommend against using Steam because Steam is basically DRM. (Yes, this varies by game and can be argued over. But it still definitely tries to lock you into using it.)