I don't quite follow. The author says that by entering the URL "http://avlidienbrunn.se/@twitter.com/@hehe.php", the extension is fooled into autofilling as if the browser was on twitter.com.
What's the difference with simply going to "http://twitter.com"?
This looks more like a bug than a vulnerability, what am I missing?