"The PSF blog post says the plan was to build tools for automating [ ] package...
"The PSF blog post says the plan was to build tools for automating [ #pypi ] package reviews “rather than the current process of reactive-only review."
This would be a fun crowdsourcing thing to do. It would have the same problems as bug bounties and CVE reports from the public, but it would be fun to write one of these.