add(new ReflectPermission("suppressAccessChecks"));
//these are required for server-side scripts to be able to
//invoke remote EJBs.
add(new SerializablePermission("creator"));
add(new SerializablePermission("allowSerializationReflection"));
add(new SerializablePermission("enableSubclassImplementation"));
add(new RuntimePermission("reflectionFactoryAccess"));
//by default allow the scripts access to any credentials of any user
//we don't consider the scripts malevolent.
add(new PrivateCredentialPermission("* * \"*\"", "read"));