In 4.3, they silently included the App Ops configuration to offer gating of permissions. Mixology doesn't need Calendar access? Turn it off.
BUT, that said, plenty of apps DON'T ask for too broad permissions, and sometimes you'll even find that app devs will put notes in the patch notes explaining why they need to increase permission scope (if they do).
I don't know about this feeling about installing the wrong package can mean doom. Doom in what way? This seems a bit silly.