The AddScript API opens the possibility of code injection in Script Analyzer. The AddCommand API prevents this.