I haven't read all the details (I'm just going by the snippet you posted in your message), but the idea of a 'host-proof' application where don't have to trust the host seems fundamentally flawed.
The thing is that the application is provided by the host, so if you don't trust the host, you can't trust the application.