This request is similar to ones we have had in the past - e.g Allow classic confinement for postman-agent and System-files under .mozilla/native-messaging-hosts . As such, access to native messaging allows snaps to escape confinement and so is akin to classic confinement.
Would it make more sense in this case to use system-files
as in the second case above since this is perhaps clearer overall what the result is to a user (possible sandbox escape), and would be more in-line with how this has been done historically for other snaps?
Also in either case we would want to perform publisher vetting as is done for Process for reviewing classic confinement snaps due to the security implications of such a request.