Keep in mind, in the really malicious cases where an extension has changed hands, they often just sell the credentials to the Google developer account, so this won't detect those cases.
As long as you don't use that account for anything else, it's seamless.
Legalese isn't going to stop that.