Keep in mind that non-sysadmin jobs and uses of xp_cmdshell will be under the user account set in xp_sqlagent_proxy_account. Therefore, execution will be under that user's context. If the account is a local administrator on the box, they will have that level of access.