Nice catch. Is it an issue though when the script injection only runs within your own browser session?
No. That in itself shouldn't be a cause for concern. Local users can do anything to their own machines already. It would be a concern if you persist this to then later be loaded by someono else's machine.