Aside from profiling, can these custom URL handlers also be used as an attack vector on other installed applications?
That is, assuming any of those happens to be installed and have a (input sanitation related) vulnerability.
Maybe I'm just seeing ghosts here. But the idea of a web site pushing malicious links to whatever software may also be installed on the same machine, isn't a very comforting thought.