That was actually my first thought. There was the story last year about replaying the typing of a Google Doc[1], and as it stores the time between keystrokes it struck me that an attacker could feed document you've written into an extension like this but in reverse, thus typing with exactly the same signature as yourself (at least in respect to the gap time).
[1] - http://features.jsomers.net/how-i-reverse-engineered-google-...