>>7764339
Erm, I don't know javascript, but I'm fairly certain you can execute code arbitrarily since the rickroll was performed using a js method.
Now the limit to what an attacker can do is constrained to whatever warosu or the XSS origin (e.g., catbox) has access to, in theory. I'm not completely sure what all that encompasses, so it's better to play it safe.