I've only heard good things about this product, in terms of their non-tracking/non-logging policies.
However 2 red flags immediately just went off. First, their installer is 500mb. Half a gig? Its a VPN, something that can be done extremely secure with builtin software and/or openssh. And it denied installing itself until I gave permissions to access my downloads folder.
These seem like glaring issues to me as a new user and entirely antithetical to what Mullvad claims to be doing.
The downloads folder access thing is because Apple made it so. If you run an installer from the downloads folder it will need access to the downloads folder. This has nothing to do with Mullvad, but is a permission check macOS puts on all software. The Mullvad VPN app has no code for doing anything in the Downloads folder specifically.