On behavior control: You need to have tools to solve this issue. We have a management console for the in-JBoss mode so that you can view all applied advices at runtime. We will be working on IDE and standalone reports as well.
I think we can address some of the security issues with signed jars and some of the built in security features of the VM.