Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...
Because it inspects the disable directives themselves, it applies to files of any language that supports them, not just JavaScript, when linted with the matching ESLint language plugin (for example ...