Should we use our funds to test for fake or malicious wallet? The points you stated above may be right to some extent but to be frank, you have to make sure you are downloading these wallets apps from the right source, which everyone knows as their official web. Play store, can no longer be trusted so even if you are downloading from Google Play store or other official stores, you should make sure that the website redirects you there. Don't click unknown links to download so as to avoid downloading Trojans or malicious apps.
This way, you don't have to test the authenticity of the wallet with your funds or having to try a decoy just as you stated in your op.
As I said, if you are willing to lose an amount that is negligible for you, like US$3 - 5, after all, this is the best way to know if the application is malicious once and for all, unless be more complex malware waiting for you to raise a considerable sum to run the scan. GPG signature, source on github and official website checks are essential forms of verification, in addition to a brief search on Google, forums and other communities for the wallet name.