The kind of person who blindly runs commands also blindly runs any .exe or .bat they download from github which is not any better.
Of course in an ideal world there'd be a perfect GUI for everything, and we've gotten a lot better at that in the last few years. But it's not like windows is lacking in things that are only configurable through CLI or the registry (which is even more opaque). I'm not saying Linux is perfect, just pointing out the hypocrisy.
The attack vector of convincing users to do stuff exists regardless of whether a niche GUI exists somewhere to do . The only proper defense against social engineering is a) training and b) following the least privilege principle (which neither Windows or traditional Linux desktop's permission model properly, as the current user in either case has full permissions to retrieve extremely sensitive credentials such as browser cookies without interaction).
Trying to defend against this from the perspective of de-normalizing the CLI is like defending against drunk driving by adding a bittering agent to Guiness beer exclusively.
As for clipboard highjacking, I am well aware, which is why any decent modern terminal emulator should a) strip escape codes by default and b) support bracketed-paste, to prevent immediate execution of a pasted command. If yours does not, please consider switching to a safer alternative (such as kitty).