If you only see a blue square above, congrats! RequestPolicy is blocking jar URIs properly.
If you see two squares, one green and one blue, cross-domain requests can be pushed through using the jar scheme.
If you see anything else... are you even using RequestPolicy?