Why? AFAIK original source is never reviewed, only the change in nixpkgs. So if the original is compromised, the malware will make it to nixpkgs.
OpenAI and Anthropic both provide free credits for OSS.
Smaller models feasibly can review every commit IMO. Would not be cheap for sure, but also would probably be cheaper than a single fulltime employee.