The arch team seems to think differently based on how they reacted to the compromise. Something doesn't have to be locked down from the start in order to be compromised.
Not being willing to knowingly and actively distribute malware does not mean they don't agree with OP. All the "use at own risk, no vetting" warnings all over the AUR and wiki support OPs claim if anything.