I really don't know, I guess the basic proposal will be something like Android: tapping the package, approving an alarming confirmation window about possible dangers, ...
But if we obtain an API, parallel stores could emerge with really good UX and maybe security addons (indipendent review, web of trust, etc.).