I think you raised a very valid and accute point here. I just installed a new laptop and confronted with Snap and Flatpak for first time to get some old familiar apps insttalled, and I noticed too that in many cases it is "random dev" doing the packaging.
Now, I dunno the #security implications of these technologies, but I assume a malicious packager can do a lot of.. malicious things.
And esp. for #PasswordManager your vault becomes your most valuable digital possession.