This is one part where it should really just be done by AI for 99% of the cases. Just have a security focused AI model that is biased towards flagging things a bit more conservatively.
Only apps that get flagged by the AI reviewer then have to go through a separate, slower human review process.