Hi, it seems like the only real threat here from the code created by TGC is the social media code which as far as I am aware is using suggested methods and the appropriate SDK's. That doesn't mean it's not possible to create an app that allows information to be hacked. For example if you sent un-encoded http data it is possible to hack it the way they're describing in that article. It's generally your own responsibility to make sure this is made difficult for the hacker.
You can be sure that we are making the built in commands as safe as possible though because we are using them in our own apps

this.mess = abs(sin(times#))