I am targeted by state-sponsored hackers and thought it would be useful to have some form of verification for downloaded files... Especially those dealing directly with your Apple account. My Apple account is protected by two hardware security keys but still... This kind of software has a big attack surface due to its networking ability, multiple connections to localhost and external hosts, all tied to a different PID. This is not like downloading a PDF reader for sake!