The situation with CrOS firmware is apparently more complex than I thought. Now that I'm running the default Recovery firmware with both hardware and software write-protect disabled, I'm able to read the Intel Management Engine code with flashrom!
I'm completely baffled by this bizarre behavior, although it may begin to explain why "the hack" doesn't always brick the device. Under current conditions, software write-protect can be enabled only temporarily, since it resets to disabled when I reboot. It appears to me that only the CrOS version of flashrom supports the software write-protect feature.