I am involved in this, what i want to say is that openaps are not the best option anymore, and pumps of metronic are not required anymore, android app & other pumps what we use right now.
With the poor state of Android security at the moment (in a nutshell, Android 9 Pie was just released while the previous Oreo release is installed on only 12% of devices), i cannot imagine anyone would want to connect a device that "can easily kill you" to an Android phone.
Most non-technical people using this DIY solution are probably not even aware of this...
The way it works make in sort that it can't kill you easy at all, the system does not regulate bolus insulin which is without a limit, but a basal rate which is basically a rate of insulin distribution from slow to fast, even the fastest mode will not kill you, and if the system disconects for some reason pump uses a default average speed.
Most non-technical people using this DIY solution are probably not even aware of this...