In case of an API, it makes perfect sense to allow crossdomain flash access. After all, this is what an API is made for, allowing access for third party services.
It is only problematic if you don't have proper authentication, e.g. when a flash app can use the cookie of the user to authenticate.