Perhaps this helps with trusting the password manager but it looks a bit complex to me. Personally I'm more concerned about when I enter a master password that if there's a Trojan on my computer it's game over. As most password managers are an encrypted database of sorts once it's encrypted all your passwords are out. The only protection against that is some sort of 2FA.
I guess if your system is compromised then password security becomes gravely threatened, no matter how secure the password manager may be. The only partial solution I can think of is to have the OS sandbox every application from every other.
The only ways I can think that would be able to prevent this are:
1. Physical non-networked device password manager
2. Really creative usage of SELinux
3. QubesOS
And in reality, #1 is kind of how RSA tokens are used. Of course, physical can be lost, stolen, and all that. QubesOS takes a ton of resources to run effectively, given everything is VM'ed and contained with a capability system.In all honesty, I could see buying an Android at a Pay as You Go place, and repurpose it to be a offline password manager. Never connect it to wifi, BT, cell. And any APK's you need you load via microSD card and USB.