It scans any subfolder, except the profile folder. The user isn't supposed to store anything in the root, except the profile folder, and "Received Files" should be inside the profile folder.
It just scans it, and if the file extension is "txt", "exe" or "dll" it checks if there is an update on the server, there is no security problem.
Apart from that, on stationary installations, profile dir is supposed to be in %APPDATA%