You are giving the plaintext to code that has (at best) the same trust level as the server itself.
What data is it safe to give to that code, that isn't safe to send (in a way that can't be mitm'd) to the server?
> That's ridiculous. Integrity checks exist for many crypto-systems, don't perform crypto - they are an extension.
I'm not sure what you're saying here - you might want to clarify exactly what you mean.
In doing so, perhaps you could tell me why you think "browser plugin validator + untrusted JS crypto code" is more secure or otherwise better than "browser plugin crypto with no JS".