Earlier quoted context omitted.
Obligatory mention of capability based security goes here. We really need a way to run untrusted code and give it just the files we want, at run-time .
Obligatory reminder of the human angle here: we need also a way for untrusted code to not be able to nag the user into granting them extra permissions.
You never get nagged to take $5 out of your wallet to hand to an untrusted person, why should you get nagged to drop a file into an application you don't trust.