If Casa had access to mobile keys then it would make us a custodian, which we're quite careful to avoid becoming since our business isn't set up for it nor do we KYC clients.
Casa open sourcing the app wouldn't guarantee that mobile keys couldn't be stolen, just like how coldcard being open source didn't prevent keys from being stolen.
The only way to guarantee that a malicious Casa app can't steal the mobile key is to swap it for a hardware key so that the app never has access.