Is the npub entered the apps developer? Not sure what I'm getting here above the gpg signed app releases and a storefront.
You are checking with your WOT if you are installing the app your follows follow
Does the store also validate signing key (ex. for linux apps)? Or is this only for android and that's left to the package manager/installer?