We (ClarityAd) do this for major ad platforms. We use a mix of static and dynamic analysis to assess risk. We've been able to detect and stop major exploit kit campaigns over the last few months. Ads have specific expected behaviors and their SWFs are not supposed to generate code dynamically.