In my opinion, this is one of the most secure options.
Pass is a short bash bash script (very little code). It passes the encryption to a dedicated utility GnuPG (out of which only the AES and cv25519 routines are used).
You should use smart card to store the GPG key. Every touch of the security key gives out only one password. So if you copy the HN password, other passwords such as your bank password is not at risk.
The missing part is integration with browsers, which increases the attack surface (although it’s minimal here, since only one password is at stake), but protects against phishing.
Pass probably doesn’t need an audit, since you can just read the script.