Literally none, if I have keyboard and mouse input it means I can already change that file. From a unix point of view this process runs under my user so it has access to ~/.claude. Absolutely no security is gained here. It could launch a UAC prompt or equivalent if it were really worried about true physical access. Flat out refusing means its a trash product. This kind of stuff works perfectly on Codex. And let's be real it would be trivial to have it code and run a program that gives arbitrary file access.