I use enpass a lot, but my password is quite long and takes ages to enter.
Both mobile apps allow for biometric unlocks thanks to their respective TPM modules. I would like to take advantage of that since there is no biometric authentication for the Desktop app.
First you would link the two devices through a shared secret (prefereably QR-encoded). After that the Desktop app would be able to receive the password encrypted with the shared secret via the local network.
The Desktop app then decrypt the vault as usual.
Voila: Biometric unlocks for the Desktop app.
When properly encrypting the password, this approach shouldn‘t be vulnerable. If you have access to the screen and keyboard/mouse to view the passwords you already have physical access to a machine, enabling more meaningful attacks.
The specifics are up to you. I‘ve been really happy with your additions and I think you could implement this is a save and easy to use way.