The permission model is messy but made much worse by the volume of SDK code that is actually in most apps today. SDKs ship as big blobs with their own manifests and if you build in the SDK then you are collecting their permissions even if you aren't using the code that needs it. And given that virtually zero consumers choose apps based on permissions, there is little incentive to pare down the list to the minimum needed.
android.permission.RECEIVE_BOOT_COMPLETED is really the only thing suspicious in that list since this is used for a few more old school malicious behaviors. Complaining about android.permission.INTERNET is frankly hilarious since that permission no longer does anything (every app has access to the internet).