I feel like flathub and many App Store-like programs that install flatpaks do a good job showing app permissions, whether the apps are OSS, and whether the developer is verified.
I don’t see how it’s significantly different than the status quo on Windows/Mac.