Overextending that analogy:
But the issue is the author effectively saying "this project's source code undergoes independent security audits prior to each release" and then being paid to include an un-audited blob.
In both cases person is being paid to deceitfully and deliberately abuse the trust placed in him.