User do not look my face (not a site member) had the following on their sandbox:
[[embed]]
<script type="text/javascript" src="[link to script]"></script>
[[/embed]]
This did not embed, but shows an intent to add what on inspection looks to be a suspicious script to the page. (Full page source available on staff request).
Given the otherwise mundane nature of the draft page, I find this behavior curious. I feel at minimum we should send an official warning and ask about their intentions, though we could also discuss further actions.