You could argue technicalities for either, but semantically, it's off by default.
The add-on is implemented as an "embedded webextension" which is wholly contained by an outer "bootstrapped add-on." The bootstrapped add-on controls whether or not the embedded webextension gets initialized, and that's all it does.
The bootstrapped add-on is literally just this one file: https://github.com/mozilla/addon-wr/blob/59659431fd2a75c33ac...
The outer shell is on by default. The embedded webextension is only initialized by the bootstrapped add-on if the user manually flips the "extensions.pug.lookingglass" preference in about:config. That preference is off by default.
> why not just have the user actually install the extension at the time of consent, rather than prefetching?
That's what we're moving to by pulling the add-on from Firefox and posting it on AMO.