I personally think you’re on to something with tying companies to the reputation of specific natural persons, but I don’t think that is where we are going anytime soon.
Although...I'm not necessarily opposed to that. Companies can change names and ownership a little too easily. Making it painful might help some things.
This can be gotten around easily by making a separate Google account for the extension. It would require using gmail rather GSuite (without transferring over the entire GSuite domain.)
Google/mozilla don't add legal language because legal language doesn't make something illegal. They can say "we'll remove your extension if we find out you've sold it", but they way they'd find out would be that the extension now serves malware anyway.
1. Permission to operate on any url page loaded locally and being able to modify the html/insert html like the clown image
2. Being able to webRequest http outbound to <any_url> where you could exfiltrate data.
I thought there was a way to insert html into any loaded page without having access to send outbound network requests.
If that is the case that it’s separate if the chrome extension were to be sold and the manifest were changed to allow nefarious behavior you would know.
Even manifest changes aren’t “scary enough”.