hmm, I don't know tbh.
basically - a standalone app that signs, but also holds all your group chat state? then other apps just call into it to get data to display and request signatures?
feel's like you've just pushed the threat (and requirement for good security) down one level. How the decrypted data is treated is also really important.
