PPS. I spoke to Niels immediately after Elena's talk and there are two useful things we can do on Downloads and/or Packages: showing the capabilities requested by a package (by parsing its Aegis manifest) whilst a user is browsing the apps (before having to install it), and making the autobuilder check that an app doesn't request any privileges which aren't available to apps available through Extras.