Have you tried locking down NTFS access to the scripting DLL?
Do you want to run some of the WSH commands and block others? I'm not certain you can block certain method calls out of the box. My initial suggestion is to run filemon and regmon in a isolated environment to see what is access and see what can be blocked. That should help you understand what is access and locked down.
Steve Schofield
Windows Server MVP - IIS
http://weblogs.asp.net/steveschofield
http://www.IISLogs.com
Log archival solution
Install, Configure, Forget