Ah, but that might skew the results... maybe not too much, though since it's only manipulating the root document? However, cross-domain permission would be broken for javascript inside the site.
If you look at the bottom of ui.js, you can see I tried a brute-force framebuster-buster. It does notify the user that the site is trying to break out, but it also catches legitimate outgoing links. It needs to be polished more before I can release it.
This is issue #1 on github for the project, BTW.