Assuming this is happening because command line-only apps cannot be stapled but i would assume that once the machine is connected to the internet it should be checked and allowed to run.
Steps to reproduce problem:
- Download signed and notarized command-line only app from internet
- disconnect machine from internet
- run command-line app
- app is prevented from running with "this app cannot be checked for malware error"
- connect machine to internet
- run app again
- app is still prevented from running with same error
If you re-download the app and make sure machine is connected to internet on first run then app can run with machine is not connected to internet.