What you are describing is a specific scenario based on specific solutions. I see multiple things going wrong there.
Chrome shouldn't access your credentials without telling you what it's used for. Chrome shouldn't expose cryptographic identities in incognito mode. The Yubikey's output is vague.
What can we learn from that?
Chrome has shortcomings in this domain. Just one monochrome LED is maybe not enough output to give reasonable feedback.
My online banking security system is called chipTAN and uses a small, monochrome, low-res display to give essential information for what is being processed which I need to acknowledge. That works well, but is also a single-purpose solution.
For identification on the internet, a solution based on GPG seems reasonable. Imagine a small display that shows the receiver you are identifiying to, the identity you are using, and for how long the identification is valid, and then you can acknowledge that.