Well, there is NIP-07 (browser extension) which is somewhat better than just blindly trusting the client, but it just moves the trust to the extension jnstead of a client.
There is also nsecbunker, which I am not entirely sure how it works yet.
If there was a hw key too, that would certainly be also very cool, tho I am not aware there is such a thing yet