I feel like there was a WECG issue discussing something similar, where the NTP could host notifications from extensions. (I don't mean via the notifications API)
From memory the vendor sentiment wasn neutral to negative, though could be wrong.
One method could be for the ext to check some sever endpoint for alerts, then display them (on any page I guess).
Obviously though that doesn't work for every extension.
On the vendor side, perhaps if the extensions page had another side menu item, under "Keyboard Shortcuts" that hosted what you're talking about.
It could show a very neutral colour indicator (akin to mobile app badges) if there's some alert.
In my opinion, that will be misused immediately, not only by bad actors, but probably by commercial publishers.
So maybe if it was ASCII text only (not rich) and restricted, e.g. 1 item at any time, no way to know if dismissed by user.
I think your problem should be addressed, imo.