Earlier quoted context omitted.
The issue is not that a manual review process should catch bugs. The issue is that Android’s permission system allows it.
Who said anything about bugs? The point is to do something proactive to stop apps that don't conform to your policies (whichever they may be - maybe you don't allow collection of data, or using a specific interface, definitely not malware, etc.) instead of just reacting, and even that too late. Apple is at one extreme blocking even legitimate things for obscure and esoteric reasons. Google is at the other, letting al…
I’m saying that with millions of apps in the store and seeing that all app testing is black box testing, the reviewers are not going to catch most things. The operating system itself should not allow certain things. There is no reason that most of the permissions that SpyPhone needs should be allowed by Android.