

more importantly, they don’t recommend that users use the AUR repository (that isn’t to say they are opposed to it). Some advice they have given is to review what the dependencies are before executing the package with an AUR helper or manually.
Just to make a point, there is a surplus of these non officially supported (from OS developers) repositories, such as the terra repository for fedora. It has the same vulnerability as AUR, and yet that is targeted for new users.
Much like how fedora doesn’t officially support Terra, arch doesn’t support AUR. There is a reason why it’s called AUR (arch user repository) over ASR (arch supported repository). AUR entails that it is not supported by arch.

it’s not managing, as you seem to imply, it’s just hosting.
Arch hosts the AUR repository, the maintenance of the packages is on the developers who developed the package.
If someone sneaks in spyware or malware inside the makepkg, that isn’t arch’s fault, that’s the maintainers fault of the makepkg.