I understand that of course, I'm much more curious why you think this is a concern for people, and/or why you consider this an effective protection against said unknown actors.
Wouldn't it be far easier to enumerate what you want an app to access?
Enumerating what I do want an app to access is handled by Gatekeeper.
...and all its children, which is effectively the entire operating system
> Enumerating what I do want an app to access is handled by Gatekeeper.
Gatekeeper is not capable of this.