One might posit that you're repackaging a fOSS project from somewhere with no clear ethos.
If they don’t trust you, it’s their right, but then they should just not use the software, instead of writing this type of caustic comments. Poor form in my view.
Keep up, it looks amazing!!
You seem to have pointed out but equally not registered that you identified exactly the issue: if your readme is filled with red flags, no one is going to invest their time (which is what you are asking for) looking at your code or trying it.
I completely understand as a developer how the “marketing” (readme) of a project may not seem that important or that it should be super accurate, and that it can be easy to fall into the pattern (as can be seen) of looking at every comment that brings voice to criticisms as being “negative”. You’re simply too close to the problem and are therefore only seeing the trees for the forest, while everyone is trying to tell you that you should probably remove the giant fence in front of the trees.
Should a user call people posting their software here state actors and the such? I really don’t think it helps anyone.
Rather, they should lay out thier points, suggest how the author could change their mind. Alternatively direct their warning to others if they feel their conviction that this is malware is unshakable.