I can't see them being able to do anything malicious, since
javascript is clientside so they'll only be able to affect there
own machine !

Can you enlighten us DeadEyes as to what they could do ?