The expense to review them deeply used to be large, a few years ago. There should be a review process that consists of putting the source code in some escrow build environment and letting an LLM do a full audit. What would that be, a few bucks at-cost?
Okay, can you concoct some prompt-injection-like scenario where you can fool increasingly sophisticated agents about the presence of your malware? Sure, maybe. It's MILES ahead of where both major app stores are today, though, where you can find obvious scams that sailed through review just by looking at their description.