From https://wiki.archlinux.org/title/Arch_User_Repository
Warning: AUR packages are user-produced content. These PKGBUILDs are completely unofficial and have not been thoroughly vetted. Any use of the provided files is at your own risk.
Warning: Carefully check the PKGBUILD, any .install files, and any other files in the package's git repository for malicious or dangerous commands. If in doubt, do not build the package, and seek advice on the forums or mailing list. Malicious code has been found in packages before. [3] [4]
The Arch Linux community makes it abundantly clear that the AUR is not a trusted package repository and you shouldn't install random packages without vetting.