I'm surprised that Mac doesn't have a built-in firewall that warns if an app installs something that listens on a port. They advertise OSX as being "secure by design."

The built-in firewall does exactly that. It may not do that for things that only listen on localhost, though.

