

I had the similar comment about PKGBUILD/templates. The package definition is far less likely to do something malicious than the software you’re installing; it’s indeed a vector - a hypothetical AUR “git-plus” package could install git and a virus at the same time - but frankly I’m more concerned about upstream.
They do keep trying, don’t they?