if you don't trust microsoft with telemetry, you shouldn't trust extensions written by random people either
There's no coherent threat model here. There are a million different ways to shoot yourself in the foot and compromise your codebase before we even begin to consider what Microsoft can do with the knowledge of what buttons you press sometimes.
MS have a history of being hostile to open source, but have been able to launder their image somewhat.
My threat model is Microsoft selling bogus "productivity enhancement" features to customers, pushing duplicated features, collecting data on costumers to acquire business sensitive information, and using marketshare as leverage to strangle better products.