

this isn’t healthy:
True, but not in a way that SnapPakImage is going to fix.
What about that isn’t “healty”?
You are basically downloading and saving the signing key of docker to the currently recommended place with appropriate permissions, and adding the docker deb-repository, explicitly stating that it should be signed by that particular key.
If you don’t trust docker, don’t add their repo. By the same logic, the Flathub repo is an “obscure repository” too.
E.g. cut currently still existing economic ties, exclude ALL russian banks from SWIFT, and send russian diplomats home.