If by malware you do genuinely mean those that exploits vulnerabilities on your system to gain unauthrorised access (as opposed to apps that have heavy telemetry), I think apps from official sources are sufficient like Play Store or F-Droid. Malware will usually ask you excessive number of permissions. Deny them whenever possible. Installing them in second profile would make the damage contained.
But since you said degoogling, I would go with F-Droid, or directly from GitHub, where most apps are open source. Obtainium is a great tool to manage those applications. Last but not least, denying network access can block some telemetry on apps that don’t require network to function.







I don’t quite understand the problem this protocol solves that existing solutions don’t, to be honest. I think it would be great to add what problems it solves in the document.