If you think that was an example of what I think software is like, then you probably shouldn't comment on it either. I'm just commenting on the fact that, like you said, there's always going to be security issues and using them as the scapegoat for "why" this can't happen is a bad argument.
What's the difference between running an app ad-hoc right now (via XCode) vs allowing a user to download and install any app they want. The answer is, there isn't any except for artificial limitations put in place by apple.
Anything an app that is installed could do would be the same between the store, ad-hoc builds, or installed from a download. The security is in the platform, not the App Store. How many times have we seen something slip through Apple's review process? Fortnite got a full CC flow UI through, many apps back in the day would slip WiFi tethering into their app and get through. All it would take is a simple API call with a boolean to enable or disable the "security issue."
You could always do checks to see what API calls they are using and use that as a metric of "security" but that can also be done device-side. "Hey, this app is using a sketchy API that shouldn't be public, we're going to block it."