follow "glacier protocol" guide for having an explanation on how and what to do for your state-of-the-art cold wallet.
Otherwise you're just getting trouble by buying such items from "random people". If you cannot verify the software / hardware I would definitely avoid any external system. It0s not an option it's a no-no situation

In theory i totally agree, but in practice it is another story. This implies to avoid every non open source software. And even for open source software, very few people are able and have time to understand thousand lines of codes. For hardware it is even more difficult to analyze...
This may not be ideal but i will stick with well known and reputable name/brand