Don't be obtuse. I can tell the difference between yt-dlp with 130,000 stars on github and some AI/crypto shovelware or a Spotify unlocker downloaded from a .ru site.
And the point isn't that it's impossible for me to get it wrong, it's that it should be my choice and my business and I'll accept the responsibility if it's less easy than I thought. The Apple types can have an easy mode where Apple decides what's safe. We can have it both ways.