How about running the facebook javascript in a sandbox? Such as proxying the document.createElement and document.getElements* methods for the initial script while breaking it for everything else?
Put another way, how do we determine if the caller of some of our js is malicious or is us?