It's a heck if a lot better than a random smattering of shared libraries getting pulled into a random high-priviledge context which also inherits some other context from whoever is asking for authentication. Polkit gets a lot of flack but PAM is absolutely mad.
On the other hand, maybe adding a JavaScript interpreter to Linux's trusted computing base isn't good news...
[1] https://mastodon.social/@pid_eins/112353420303876549
[2] https://www.freedesktop.org/software/polkit/docs/latest/polk...