Because the Steam Workshop is wildly insecure and nobody cares about it and probably never will (gaben pls respond).
It Automates the process of locating, unpacking, finding luas & other files that can contain lua throughout addons, opening the lua and manually checking the code.
It also offers the option to backup the addon into a seperate folder for safe keeping and later dissection.
Example Video: https://streamable.com/belp04
An awesome command line program I found for scanning folders for common malicious strings in glua; compiled by me. If you dont like it compile a binary of your own :b
https://github.com/ProtoGrace/Gmod-Backdoor-Scanner/tree/master/BD-Scan