an interesting idea would be to make a pref where all non-host player's code had to be first approved by the host. A little gui would pop up, previewing the code. perhaps it should also search for functions like "eval", "filedelete", "getnonsense", and "crash" and automatically deny the script if it has that in there.