OSs need to stop letting applications have a free reign of all the files on the file system by default. Some apps come with apparmor/selinux profiles and firejail is also a solution. But the UX needs to change.
replies(5):
In my case, I either use apt (pipx for yt-dlp), or use a VM.