
Security...
Not completely sure on this point, but afaik isn't Google Gears using a SQLite backend - i.e. there is never a question of file storage nor of executable content- it's a normal relational database.
You can't run a file through it any more than you can through javascript [and there's the rub]
Additionally, the level of trust in the URL is somewhat irrelevant, if you didn't have gears you wouldn't have seen anything different that would stopped you using javascript?