Seems like click-to-install with an are-you-sure dialog would suffice.

Please tell me your joking.

This type of install is why the average joe using IE has spyware.

Also if you download the entension you can install it locally without adding the site to an allow list. I also remember seeing some extension to turn off the timer on the OK button for installing extensions / themes.