Exactly right on the managed OAuth being a double-edged sword. That security is a huge selling point until you hit a scope issue, like wanting to post to a private channel the connector wasn't originally authorized for. Then you're in a support ticket queue waiting for Flux to potentially update their OAuth app's default scopes, instead of just regenerating a token yourself.
The other hidden constraint is in the channel selection itself. With a native action, you're typically limited to picking from a list of channels the bot is already in. Need to post to a newly created channel dynamically based on, say, a region code from your Salesforce data? You might have to first add the bot to that channel manually or via another API call, which adds a step and defeats the 'simplicity' promise. A webhook doesn't care; it just posts to the URL you give it.
buyer beware, but buy smart