It's auto updating JavaScript maintained by some unknown that can rewrite html on any page, how is that not an MitM risk?

The html itself is rarely a lot of data, most things in this space remove or resize images etc.