Flathub has manual submission verification though, which includes the steps to build flatpaks. Reviewers (currently) would definitely catch fishy looking apps.
They've also implemented manual reviews in case of metainfo or flatpak permission changes, another thing for additional safety.
uses its own libraries and not system libraries, want to play the hit new AAA game with steam flatpak? get fucked it requires a mesa commit that was merged 8 hours a go and you're stuck on 23.0.4 and can't use the git release.
Can't you just install a git snapshot of mesa in a flatpak and use that? Then it'd be an upside
Flathub has manual reviews during initial submission though. Also they're working on automatically needing a manual review when e.g. new permissions are granted to apps
kid named finger: