Seems to me that the solution to that is to make permissions extremely granular and grade the level of review scrutiny an extension gets by its permission granularity. Then, only extensions that want to access or modify something truly sensitive would run the risk of getting smacked down randomly like this (as is always liable to happen with an automated process).
Not just "read all websites" but "read the URL only", "read the visuals but not the HTML/CSS", "inject predefined code onto only website X".
It also incentivises extensions to ask for less permissions so they can pass review more quickly.