Interesting. I'm an uzbl contributor and user. We know that quite a few things are missing yet (certificate verification is among them, though bct has a branch[1] for support). JavaScript black/whitelist is also not supported, but likely just needs a few hooks added in. Ideally, it'd be similar to the cookie black/whitelist where you can block based on fields such as originating site, site the JS was requested for, and more. A more structured configuration file is also underway[2] (though I've not done much with it).