No - javascript is executed on the client - never the server. Nothing
you can do on the client can damange the sever
*provided* the server code is safely compiled.
I guess I omitted to say that in my "safe" mode of compilation
*everything* is compiled with a safety wrapper (ie including
BIFs) - thus 
    apply(M, F, A) is transformed to safe:do(erlang, apply, [M,F,A])
   list_to_atom(X) to safe:do(erlang, list_to_atom, [X])
   Then safe:do/3 can be written with any policy you like - to enable or
disable more or less risky operations


