I recently discovered this because a few of my extension's users wanted us to create a whitelist feature. We had previously built a blacklist feature and were dreading creating a whitelist also, and figuring out how to educate users about what these two features are, and how to use them. Then I discovered that Chrome (and Brave) offer this whitelist feature on all extensions. Problem solved!
Sadly (and surprisingly), Firefox appears not to offer this feature.
Firefox's current strategy is to manually label a handful of extensions as trustworthy in their marketplace.
The rest as untrustworthy so that when something bad happens they can throw their hands in the air and say, "we warned you?"
The moment you can start modifying the DOM you can essentially start sending network traffic.
Extension can list this permission, and request access to specific website on demand.
Chrome has supported this for a long time, but I'm not sure if Firefox supports this permission or not.