And are there any plans to have a 'named filter' control within widgets that would let you change the operand?

It is possible. There was the question regarding this option.

If you need the filter for the measure, make it searchable, as Peter said. 

If you want to filter calculated measure, try to change it to classic measure with COS expressions in the measure definition.

Hi, John!

I think it refers not only the "importing xml" cases but also any installation of any 3rd party tool or solution to your target InterSystems Caché or Ensemble server. 

I think the Package Manager can cover some risks in this field.

Another idea relates to docker technology: install the "unknown" but interesting solution into the docker container first and see how it works and where it tries to send the data and etc.