[1] https://github.com/arkenfox/user.js
Right, it seems to me that in many ways it'd make sense if we had the option of restricting the JavaScript engine per se.
As users, if we could determine what functions JavaScript could actually perform then many of the security risks could be avoided. For example, if say we could change or randomize data in response to certain website queries which then resulted in them receiving garbage in ways they could not detect then users would be in much more control. Exactly how JavaScript would respond could be set in the browser's settings and changed as necessary.
I've long wondered why privacy browsers don't go to the heart of the problem and use modified JS engines. I'd love to know what those who're involved with browser development think about such a tactic and why it hasn't previously developed any traction.
(On my machine it's under "C:\Program Files\Mozilla Firefox\distribution".)