How trusted are the iOS/Android app compared to the "mainstream" desktop clients like KeepassXC ? I'm a bit wary of downloading a "random client" from the App Store. Are those audited/trusted as much ?

I've been using Keepass2Android [0] for a few years now (synced with the desktop client) and haven't had any issues. I'm not aware if any audits on it, but I'm not sure the risk of a developer pushing malicious binaries is that much higher on the play store than the arch/debian/snap/brew repositories.

[0] https://github.com/PhilippC/keepass2android