It generates a config file. You can read it before applying it. While Nix may be nigh intractable to write for some people, it is quite a bit easier to read, and any shenanigans would immediately be noticed.
I mostly just check the diff, and if nothing looks particularly wrong, I commit it. I mostly care about the final result. Commits are there for eventual auditing, but they're not that important to me.
I (or an LLM) can always clean things up later, and there's plenty of time considering this is the configuration for however many machines I'll be using for the foreseeable future. I used to spend a lot more time tinkering with configs that could be wiped out by a failed Windows Update.