This is why I think filesystem security needs more work put into it. macOS is far ahead of the game, but even it has its issues. Restrictions are a tricky thing, but maybe everything running on your machine shouldn't all put files where they can be accessed by every other thing.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks?
It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts.
This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.