I suspect capability models are going to get more popular https://en.wikipedia.org/wiki/Capability-based_security
It's been a real education. I talked to one of the people behind Caja and learned a lot.
Why did you not embed your language into another one, with type system that is superset of what you need?
For example, there's capabilities expressed in Haskell: https://github.com/tweag/capability
Capabilities there are tracked at type level and are subject to type erasure, if possible.
Bluefin is used in production, and as far as I know capability is not.