>The Mac App Store should already be safe, as users are free to download and install apps direct from developers
Not a Mac user/dev here. If I am not going through the store, if I don't use xcode to sign my executable, won't MacOS force the user to go through cryptic command line changes to let them install my software?