Earlier quoted context omitted.
Meh. The author of age is very experienced and known specifically for security, crypto and within the implementation language (Go). Audits are only as good as the competence of the auditors and can often turn into checklist rituals. It certainly doesn’t hurt, but audits are not a panacea.
Agreed, but IMHO claiming that a crypto library is secure without providing independent verification, is like claiming something is fast without providing benchmarks. (And both are the same in the sense that neither is a panacea.) I'm only bringing up audits because such claim was made, but maybe I should have said "independent verification" instead since it's more general.
"independent verification" is subjective. Who does the verification, do you trust them, how do you know they didn't screw up.
"benchmarks" are objective. A is faster than B, we know because of the way that it is.