Is there an implied guaranty that an application is safe if it's in the store?

The problem is that we don’t really know that the builds are really the result of one of the repositories on GitHub. It should be possible to reveal where the build came from (i.e. by build.snapcraft.io according to namespace/repo_name, or pushed directly by certain packager)