I don't think I said anything about trust. I was talking about content delivery. All the things you mentioned before are avoided using this method of delivery.
So you’ve audited the code of these apps, apps published by active criminals, and confirmed in a via reproducible build that none of these apps are a vector for VPN access, nor try to take advantage of vulnerabilities in any of the other software installed on that system.