A surprising amount of them comes with unlisted and uncontrollable connections to snooping services like Google Analytics or Sentry, I've seen unexpected redirects / tab hijacks - mostly to advertise the developer's new other extension, even fetching and executing external scripts and other resources from various CDNs is not uncommon... essentially everything their extension policies disallow.
All these violations are hardcoded into the extensions' source and rather easily scanned for automatically mind you, it almost takes more effort to not notice them.
I've stopped reporting the ones I encountered, they were never taken down, never lost their recommended badge, and all the violations remained in every next version that I checked.