Appreciate the context. But my larger point is that all of the sandboxing and plugin permission security features falls flat until you can easily evaluate the plugins themselves from social signals and even looking at the code on Github. It's one of the main aspects the people overlook when trying to replace WordPress is the developer network, reviews, ratings, etc.
Otherwise you just have to trust the random plugin publisher and the permissions/sandboxing doesn't really matter.
What you're actually saying is that network effects are strong. Those network effects are the only reason Wordpress is still so commonly-used.
But, that has very little to do with the work described in the OP. Maybe EmDash will fail to gain sufficient traction to have their own network effects, but in the meantime, doing moderation on plugins in their marketplace is still important work. Automated moderation to prevent abuse and malware is useful, and is orthogonal to the social proof you're talking about.
The permissions/sandboxing (and Clef review) IS the reason you can have a reasonable confidence in trusting a random plugin publisher.
samtp - I think you're looking for the answer to two or more problems here.
So far EmDash has an answer to what I think is the most important question (IMO). Can I trust that a plugin is (relatively) secure? Yes.That's something WordPress haven't been able to do - so I'd say well done to the EmDash team! And, if I wasn't building my own CMS (with a very similar permission model) then I would probably be trialling it right now :)