Interestingly, this is what Crome has done. The app store used to be a distribution point, but as of recent versions of Chrome it's become an exclusive source of extensions for exactly this reason. (There are fortunately ways around it, but it does minimize the threat of malware).
Correct, that's why I said "manually". I'm assuming these plug-ins are not already available in the Chrome store. I'm saying that in addition to that, Google should implement some sort of blacklisting, so that it doesn't get installed manually either.
Whitelisting would be a more reliable solution. It has snuck into consumer computing under a different name: app stores.