U5 — The extension's manifest as a published profile
One line from the 5 September index, and cheap enough to build first: "the extension's own manifest should be published as a profile… It is a grant declared in machine-readable form by the thing it describes, which is the artefact this estate keeps asking vendors for."
The finding
An extension's manifest.json already is a machine-readable declaration of what it may do — permissions, host permissions, content-script injection points, all of it stated up front. Publishing it as a profile — alongside the extension, dated, versioned — means the estate does for its own tools what it asks of every vendor.
Small, self-consistent, and it connects this site to the conformance and grant work in the September briefs. It also pairs naturally with rubric.json: a manifest declares what an extension may do; the rubric declares what it should be graded on once it does.