Seems like it would be very hard for it to catch everything from the outside. I've seen malware that only presents itself to clients with a Referer from Google or an iPhone user-agent, for example
What you're referring to is Conditional Malware. We actually do very well with that, but there are no 100% solutions. There are also things that are hard, like Defacements and environments used for Phishing Lures..
All great points