

I determine within the PKGBUILD (which I view from octopi) the URLs where code or binaries are downloaded from and then if those URLs seem trustworthy, e.g. how many stars or maintainers the github repo has. When the repo is small and doesn’t qualify for the latter criterias, I do a git clone and skim over the sources on the lookout for malicious URLs or strange code (never found anything in that regard). Also search for the package on https://aur.archlinux.org/ and look if other users have anything to say and how many votes it has.
I’d wait for sales of your games instead. I tried one fitgirl release on EndeavourOS I had from my Windows days (which ran perfectly on there) recently. Tried with Bottles and Lutris and the latter worked eventually but the performance was subpar and it was quite a hassle to get it to run as I had to try many proton versions with a lot of restarts and black screens. Steam and Heroic games run fine though.