As a side note, this is one of the reasons I'm a paranoiac about CSP. Currently Pinafore disallows all arbitrary inline scripts because I just don't trust myself to think of all the ways a malicious instance or malicious user could take advantage of a client-side webapp that talks to multiple cross-origin servers.