May I ask why you think that is?
The correct way is to create a (signed) package of your app so that it pulls in no external scripts or files. Makes updates a pain (no free auto-upgrades you get from the web) but makes the app a lot more difficult to attack.