I agree having to go to the command line is too much friction. Just clicking `overdue-invoice.doc.pif` is too little. About right is somewhere between a prompt and setting the file executable in the GUI.

I wish it would run in a stricter sandboxed mode and prompt the user on the first network requests and file writes outside of it's directory.

That wouldn't be perfect, but at least the user could be prompted for a concrete action instead of a vague "this script is scary" warning.