I would like to add:
to the list of tags:
ABBR ACRONYM
It is mark-up for those using speachsynthesizers.
to the list of attributes:
accesskey
to allow jumping to links by using the keyboard
I cannot comment on security, maybe Jeroen can. I know we should disallow all attributes/tag combo's that invoke (java)scripts obviously.
WebCT:
http://www.securityfocus.com/bid/10357/discussion/
An approach:
http://www-106.ibm.com/developerworks/linux/library/l-sp2.html
http://www-uxsup.csx.cam.ac.uk/redhat/howto/Secure-Programs-HOWTO