I've always hated the concept of certain chrome extensions having full access to all the pages I visit in the browser but sometimes its necessary. Ad blockers are way too high on the list of potential attack targets, close second would be web development extensions like editthiscookie.
There needs to be a way for webpages to indicate that they don't want any external scripts running on the page. Even a setting in chrome would be really helpful. I don't want external scripts to be running on my bank website, or when I'm working with my stock exchange website. Right now I'm making do with multiple chrome profiles but that doesn't cut it. There needs to be some initiative in this regard from major browser vendors.