The xz issue might not directly affect an anti-virus, so maybe in this specific case, it would work fine. But it wouldn't be hard to come up with another library that would make the anti-virus moot. And even in the xz situation, doesn't it affect systemd?
All bets are off when you can no longer trust low level software like this.
I am not familiar with that. From a quick glance it looks like the new HURD. But I think even there you're relying on the work of others.