Any proper implementation of the cors eval/script constraints would block extension script injection, regardless of whether webextensions are used. You'd have to run code outside of the page context, which automatically poses issues since the page is probably in another process.