I would not claim to be a oauth2 expert, but to the best of my knowledge the scopes that one declares during the app registration on the reddit side are the
upper bound of what said app is
allowed to request, and thus if there was a checkbox on alien.top's side asking whether the user wanted bidirectional behavior, if unchecked the oauth2 handshake would omit the write scopes from the handshake and the token that comes back would be read only. I have mixed feelings about the "offline" part but if it was read only, I would be perfectly fine with alien.top using my access token to help spread the rate limiting load during any sync activities for the subreddits I was in
Furthermore, again, to the best of my knowledge, if an alien.top user changed their mind and wanted to opt-in to the bidirectional behavior later, you could have that user just re authorize with the same client-id and this time ask for all the scopes. Much less complexity than managing two separate app registrations