This looks like a low priority issue to me.
Fossify file manager has the same behavior.
https://imgur.com/a/RrS8RRQ
If it helps, you can reset package manager's default app preferences to get a prompt like the pic above.
settings > apps > all apps > 3 dots top right > show system > package installer > open by default > clear defaults
I only see this as an issue if you're trying to prevent grandma from installing apps or you give your phone to untrustworthy people.
If we need to protect ourselves from ourselves opening an apk and hitting install--on accident?--then idk.
I see this as similar to another situation:
Files doesn't have network permission; yet, I can open a PDF then push print within that other app.