If someone sneaks in spyware or malware inside the makepkg, that isn’t arch’s fault, that’s the maintainers fault of the makepkg.
I don’t think that anyone argued otherwise.
I even said it in the very reply you are replying:
The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package.
it’s not managing, as you seem to imply, it’s just hosting.
Arch hosts the AUR repository, the maintenance of the packages is on the developers who developed the package.
If someone sneaks in spyware or malware inside the makepkg, that isn’t arch’s fault, that’s the maintainers fault of the makepkg.
I don’t think that anyone argued otherwise.
I even said it in the very reply you are replying: