CORS error when creating/updating study material

One negative consequence would be that a malicious userscript could modify users’ data in unwanted ways, reset their level, etc. without warning.

I’ve not tried it yet, but according to this post you can avoid the prompt when using GM_xmlhttpRequest. If I understand correctly, then I think userscripts already pose this risk.

