test(release): check that detection still works, against real publications master
Every module has unit tests and v1.2.1 still shipped with sign-in dead, because what broke was the wiring between them. This is the same idea applied to detection: load the built extension into a real Chrome, visit real publications over the real network, and assert the state the worker reaches. One site per detection route, so a failure names the route rather than just saying detection broke: standard.site is found by the origin well-known with no link tag, atproto.com/blog by a link tag plus a path-scoped well-known because its origin 404s, permadeath.com by both, and example.com is the control that catches a build which "detects" everything. Verified against a deliberately broken build: repointing the well-known probe fails the well-known-only site outright while the hint-carrying sites survive as unverified warnings, and the control still passes. Live network, so it is a release gate rather than a prek hook or part of npm test.