Your firewall rules are a file. Files can be edited.

If malware ever got write access to your rule store, the quietest thing it could do isn’t steal data — it’s delete the one rule blocking it, and let everything else keep working exactly as before. Ferrite signs the file specifically to catch that.