AUR should be scanning new uploads for malware before allowing them to be published.
What does "scanning for malware" mean? As far as I know this is a totally open question, and the only credible answers (install in a sandbox) are too inconvenient for widespread adoption.
You can only scan for known malware. Plenty of ways to write new apps to do bad things that scanners won't detect.