Also, just because we're on Hacker News, it doesn't mean every reader is equipped to audit code for security vulnerabilities.
Presumably that's the job of a professional security developer that might reasonably be expected to have checked their own similar product for this vulnerability...
Fair. I would, though, expect someone whose HN profile identifies him as an experienced full-stack engineer to be up to the challenge of spotting something as basic as an extension injecting code into untrusted DOM and trusting the results that code gives back.