Depending on your level of paranoia, you cannot assume that your xpub is safe anywhere.
A xpub is easy to spot if stored in plain file, so as long as a malicious OS process has read-access and can connect to the internet, all coinjoins are pointless.