In other words, use the same sort of sandbox + permissions model that iOS/Android apps live in. For example:
- "USB device 'Kensington 16GB' is trying to take over as your computer's keyboard. Allow?"
- "USB device 'Kensington 16GB' wants read access to your files. Allow?"
- "USB device 'Kensington 16GB' wants write access to your files. Allow?"
The latter two could be more specific about the source/target directories.