BFT protocols are typically secure if 2/3 of the nodes are honest.
>Are the resources guarding those seven nodes equally proportioned? How hard is it for a bad actor to potentially subvert one and cause it to pass bad-but-trusted data? Can these nodes be switched with other, potentially less-secure or hostile nodes? How are additional nodes added to the network; is there a credentialing process that could potentially be attacked?
These are good questions. I believe in Libra human beings decide which organizations are allowed to run a node and they build a fixed list of say 100 or so nodes one from each organization.
>Who maintains each node, what is their level of sophistication, resourcing, and control?
You don't want amateurs running nodes. This is normally where such proposals fail because if you don't have enough clout early on you won't get good node operators and this poisons the security argument. From my perspective Libra is the first team which has overcome this hurdle.
Then again hopefully everyone doesn't just run these nodes on AWS.