Like with downloading executables, have the user double check in the download prompt rather than in the download manager whether or not they want to trust the source and download/open anyways.
never-displayed