There is always people complaining about the security of GM and scripts that can steal cookies. A solution could be adding two lists of general excluded pages for all the scripts:
The first list would contain the pages where you want that no script will never run.
The second list would contain the pages where you allow a script to run but it can't access the cookies.
I know that the you can configure the excluded pages per script, but I find that this list is more something specific for each script and the contained pages are more decided from the script author. Moreover each time that you install a new script or reinstall a script, for example because a script update, you have to reconfigure the excluded pages.