#2544 made some initial steps in clarifying that c18n does not prevent powerful APIs from exposing privileged data. We should develop more detailed guidance on reasoning about the security of a compartment given the set of APIs that it or other compartments have access to.