Also the first install is validated by the devs on nsec, so I guess you trust zapstore to not have bugs, but the idea of the code is that it validates the actual devs signature which you can compare to your social follows.
Then regular TOFU kicks in for android protection
