A: This is a package delivering jack user and its home directory for OpenIndiana LiveCD. Installer automatically uninstalls it on OS installation. If you install it manually on you system, you'll have user jack with well known password.
A: When user has Primary Administrator profile assigned, he can execute any command with uid=0. The issue is that any process can do this without interacting with user. So, when there's new exploit for your favorite browser, attacker can gain root access to your system.