I'd recommend trying this: Download a notarized Mac app, delete any stapled notarization ticket (.app/Contents/CodeResources), and then trace the launch. What do you see, and does the system let you open the app? Does it say it checked for malware?
I'm running both experiments. I've tested and compared script notarization to app notarization.
You're getting apparently unusual results with script notarization. So the natural next step would be to compare against app notarization.