Resupply8986 I have to admitted I had the same issue when arriving on GOS. Overall, I don't think there's issue by using f-droid since it's widely known. But the problem is that f-droid takes time to update apps, which can lead to vulnerabilities. But since even Proton have their apps hosted on f-droid, I don't think there's a risk other than apos taking times to be updated.
For the Aurora store, the repository rely on the official Plays store. Aurora is just a front-end of play store. Furthermore, when installing apps on Aurora and then switching to Playstore you can see the apps are recognized. Which confirm they weren't tempered.
But surely Play store is the most secure because (whether or not we like the company) Google knows how to secure their products. Moreover Sandboxed play store is the recommended by GOS developers.
But, with that being said, I don't think you're wrong using one solutions or another. Because some other people on the forum use Obtainium, F-droid, Aurora ect...