And you can check the shasum of the binary to see if it actually matches that provided by the developers of the application.
A malicious PKGBUILD, which is what is being talked about, you would see that it downloads a binary that does not come from the developers and so you should not install that.
If the attack happens on the developers repo, not even Linux repository packages would be safe at that point (eg, the xz heist).
Almost true.
It is pretty picky, as it expects a certain folder structure to get all the info correct when importing. But it is fairly easy to go in and manually "fetch" the correct metadata from one of the metadata providers (Amazon, Google Books, Open Library etc). It's a chore if you have big library with many different structures, but doable if you don't want to rename all folders.