This feels like a case where it'd be good if Apple had two different messages, one for SMS filters which have a ILMessageFilterExtensionNetworkURL configured (which should get the scary message you saw) and one for those that don't (which are sandboxed to be purely device-local).
That said, Apple doesn't really handle the case of permissions changing with an app update very well, so launching your app purely device-local then updating to add something server-side a year later would probably let you get around that.
This app seems to not have the key that'd indicate it's capable of sending anything to a server: https://github.com/afterxleep/Bouncer/blob/master/Bouncer/In... (though, you know, that assumes that the build on the App Store is directly from the source we can see...)