Poison a single common open-source daemon which is used in a lot of systems; That daemon will have access to all keystrokes, window content, etc.
> The reason for that is that people who use X also exclusively use trusted apps.
Well that's just not true. What does trusted mean? Most of the software on our desktops is unaudited. We don't have insight into the entire chain of deployment for more than a handful of applications we feel like keeping up with.
On a side note, that would be a wonderful service; A man-like utility which simply displays change-logs coupled with relevant source-code diffs. Reduces the surface of trust down to one party. Something like that would require financial backing, however.