OP mostly FUD but good that people are aware of all the attack vectors.
Can't be too careful when it comes to large amounts of money.
If you are using electrum, I have published several utility
scripts in the electrum sub forum that you can use
to verify if the addresses and keys from your copy
of electrum are legit.
how can normal people use such script?

the normal people wants something safe and simple.
it was proved that the COLD wallet can be hacked. once you are hacked, you cannot recover the bitcoin.
I don't have all the answers... I assume that in the future, as
cryptocurrency becomes more popular, people will know how
to do basic things like run python scripts, similar to how most
people know how to check the oil in their car... Either that
or hire a trusted security consultant.