If there is no code required them I'm guessing you'll follow the the facebook model and grab the URL which the user is currently viewing as the identifier for the content being flagged? Otherwise you'll need the site to provide their own custom content id.
Abuse is going to be another obstacle. If everything is client side then you really can't stop any sort of abuse since you can't authenticate that the user is who they say they are. I suppose you could get away with logging the IP address with the flag request. That way its just a tiny bit hard to sent more than one flag request.