As a power user, I am concerned about the possibility of widespread adoption of your product and/or others like it.
I don't want my bank to ban me just because I use a browser extension to capture my own cookies from my own valid session and pipe them into a shell script I wrote to invoke curl to harvest my latest bank statement as a PDF and store it locally.
Supposing that your system wouldn't flag that activity as malicious, what about the vulgar things that I did to their servers while I was developing my archive-bank-statement tool?
NB. Please ignore the implication that my tool is complete or useful. It's not... :)