Makes me quite nervous too. So far each dweet is run in a sandboxed iframe loaded from a separate subdomain.
There are definitely things you can do, and I'm aware of some annoying ones. I'll just manually delete them at this point. Any security conscious person would view it with noscript and just read the javascript ;)