If he can do it, so can the bad guys.
Not quite. If he can do it, maybe some bad guys can. If he publishes it, anyone who cares can.
What about arbitrary javascript on web pages? By your logic, a Flash player would be out of the question.
Yes it would. Don't think for a second that Apple would let you sell your own browser of Flash plug-in. It doesn't mean that you are not allowed to use an existing Flash plugin or webbrowser tough.
While the 11 KB code footprint might not be all that impressive (altough I think it is), the 13 is very impressive for an IPv6 stack. I haven't RTFA but if it accepts a largeish number of simultaneous connections, I highly doubt they got it working at all with that kind of footprint.
Heck, 13KB is only slightly over the space required to load a 64 by 64 24 bits bitmap in memory. And you haven't displayed it yet.
8 Catfish = 1 Octo-puss