GOS recommends sandboxed Play Store over Aurora
Youre ultimately installing the same app either way, Aurora is just an anonymous Play Store frontend. I recall some discussion about Aurora failing to check app signatures. And youre adding an additional party to trust. But the real security concern imo is Aurora's lack of auto-updates, which may leave you vulnerable to zero-day attacks if you aren't vigilantly monitoring your updates
I see little need to explore an anonymous Play Store client when you'll be installing Play apps - likely with some kind of Google integration - & logging in with a de-anonymized account, unless you've managed to circumvent KYC laws and establish private banking