I am aware of the code signing. But if somebody at Satoshilabs sneaks in such a line, it is pretty impossible to detect.
I agree that this may be unduely paranoid, and presumably, they have QA procedures that makes it impossible to do in practise.
And I
am seriously considering buying a Trezor. It is, in my opinion, a very good idea to offload the signing to specialized hardware. The really paranoid can probably make it part of a 2-of-2 multisig wallet.
