It would be nice if Firefox provided an API that only exposed the static HTML of sites you're visiting. I don't care if an extension wants that data, it's nowhere near as sensitive.
I guess this doesn't solve injection, but there must be other ways to solve "display some additional data."
Here is a browser extension idea: inject this disclaimer into the article by estimating it from the length. How can we achieve this without the ugly
permissions?