This doesn’t solve the supply chain security issue mentioned.
Supporting tools like cargo audit would be a better choice for the entire ecosystem, not just things that are appropriate to have in stdx.
How could cargo audit help there when you don't know if a particular package has been infiltrated?