not sure what you are asking here. Any box connected to the Internet is at risk at various levels. Running Scalix on the box does not increase a potential risk. The Scalix user that is being used by UAL does not have root permission, so whatever damage theoretically could be done is limited to the access rights of that user. Can you be more specific about your concerns?