If an extension discovers a valid canary, it caches the site as canaried. If a canary changes or disappears it informs the user. A DB of known canaries can be available as a subscription (like adblock one).
To discover a canary an extension searches in meta tags for it. If it finds a meta element with content having a canary it means it has a canary. This canary has the following format . The implementation must check the signature and pin public key.