Everybody who claims Pegasus and other ATP-malware is trivial to detect has no clue what he's talking about.
Which has no way of acknowledging false positives [1] except by turning it off completely (in which case it will start spamming you to please re-enable it).
[1] An app that for rooted phones allows mounting the external SD card as a mass storage device instead of via MTP [2] unfortunately doesn't work with SELinux enabled, so it automatically offers to turn it off (and later back on) for you, which for Play Protect is apparently enough to classify it as highly suspicious. [2] MTP is just plain awful – slow, can only do one operation at a time, doesn't preserve file dates, limited compatibility, sometimes doesn't show all files because it's based on Android's media scanner database instead of the physical file system contents, etc. etc.