Subtle risks abound when you allow people to run code on your site. Wonder what nastiness we’ll deal with once the W3 Cross-Site XHR spec becomes common across the three major browsers.