Earlier quoted context omitted.
That's a collosal red flag.
It depends on what you're looking for. It's similar to other third-party component libraries out there. There are open source and closed source ones. With the closed source ones you can take a leap of faith and trust the developer of the project, how it's documented, what it does, and decide whether or not to use it. If you submit to an app store, they can decide whether to approve it. There are closed-source third-p…
Security, for starters.
There is no way around this.
> It's similar to other third-party component libraries out there. There are open source and closed source ones.
You're trying to side-step the fact that a random user uploaded binaries that were crafted to do god knows what to the host's computer in a way that circumvents basic auditing and security checks, and did so while hijacking/piggybacking on popular software projects.
You can try to spin this any way you want, but you need to be crazy to download and run these binaries as there is zero assurance they are not malware.