In this case it's significantly more secure though, as the exact request and response are signed and a third-party you trust (your browser) is deciding if that signature matches.
Today’s browsers trust all user-configured proxies implicitly and no other proxies at all, so providing a signed copy of the GET-only AMP content, it can be safely cached (the “replay attack”) without needing to trust the cache, because it’s signed plaintext.
When you permit a proxy to replay your content, it's just caching. It's not an "attack." (If the proxy can replay your content without your permission, that would be an attack.)
"AMP pages must...Contain a <script async src="https://cdn.ampproject.org/v0.js "></script> tag inside their <head> tag."
https://amp.dev/documentation/guides-and-tutorials/start/cre...
Their special tags[1] won't render without it, and I suspect Google won't include it in their SERPS if it's not valid AMP.
[1] https://amp.dev/documentation/guides-and-tutorials/learn/spe...