This is not that exciting: a malicious XSS or CSRF and PAF! an attacker writes on the user filesystem!
ie, it's likely to be exactly as vulnerable as your computer. If you open a vulnerability in your extension and someone exploits it, it's the same as a flawed program that allows input being attacked. If they eval JS from arbitrary sites, that has nothing to do with the security of the system, only the security of what you installed.
To make matters harder, experimental API extensions aren't allowed in the chrome extension gallery - you'll have to go looking for unapproved, file-system-accessing extensions to expose yourself in the slightest to that danger.