frdoid is an alternative to google play that only provides open source apps
amber is an "isolated signer" which keeps your key and all it does is accept requests to sign things and has a set of permissions controls about what things it will automatically sign, or it pops up and asks you to consent
amber helps you protect your keys from being compromised by a bug in amethyst or other apps... and it also makes it safer to experiment with new apps that do other things, like "pokey", which vitor is always talking about lately, a nostr app that specialises in notifying you of events that you might be interested, like DMs or replies or reactions
Yes, I use Obtainium and F-Droid (via the Droid-ify fork) for most of my apps, fantastic software! 🫡
As for Amber, is a bug that exposes my nsec a significant threat? Also, how does it protect your keys? I understand the signing aspect, but couldn't a bug theoretically expose them in Amber as well?