Ran it with Little Snitch installed (why bother looking at the code when a malicious actor can just upload a modified binary anyway?) and the claims seem to be legit so far.
Presumably need to look at code, build code, and compare binaries.
Why not just do this yourself before commenting?
Because this is a community, and I appreciate having had the question asked and answered, as do many others I'm sure.