> Then click to allow when the system dialog asks if the sample app can control TextEdit via Apple Events.
Seems to require the user to explicitly give the application permission to escape the sandbox?
Seems to require the user to explicitly give the application permission to escape the sandbox?
Even if TextEdit files were quarantined so you could not execute them, you would still be able to do harm, such as snooping on the user's recent documents, or trashing the disk by overwriting files that TextEdit has access to. Likely it could even install a LaunchAgent to run arbitrary code outside of the sandbox as well.
There's already a security dialog here that warns the user. Maybe the user's imagination doesn't run wild with all the ways that the access could be abused, but they _were_ warned.