2. The threat model makes no sense. Why would Google send you to a compromised vendor of cheap devices with weak radios to falsely secure logins to your Google account, when Google already has control over your Google account?
There's a simpler answer, which is that the only vendors that have Android NFC U2F devices are China-based. The YubiKey doesn't support U2F over NFC (at least last I checked). That's why they previously had you get one YubiKey and one Feitian. On that assumption, the most rational thing for Google to do if they have good intentions is to suggest the leading Chinese security key in the short term, and in the medium term, white-label that key's hardware and flash their own firmware (or at least firmware they've audited) onto it and rebrand it, which appears to be exactly what they've done.