This is a usage problem that you will find on all types of catalogs, even on much more professional solutions like CMP.
The basis of a catalog is to be a userfriendly entry point for presenting sources, internal sources that you have set up yourself, sources that come from a trusted publisher etc..
If the uses are bad, too bad for those who do anything.
In my previous answer, I talk about more important problems, like for example the fact that a trusted editor releases sources with critical security holes because they have been hacked.
Of course this issue already exists, but the impact is much smaller today than with an open catalog where everyone could subscribe and manage the life cycle of these addons.
And this is just one example, there are many others.