macOS does this automatically for some stuff, but not for anything OSS related.
eg. prohibiting reads of ~/.ssh is an easy security win with few downsides. Tools that genuinely need access can request it in the package yaml and then tea can prompt to allow it on first run.
Ideally I think we'd extend the macOS security feature (no idea what system controls this, you see it if you do a find ~ for example). However I don’t think that's possible.