For the overwhelmingly paranoid, there is one further possibility: if Microsoft were to make packages available in its repo with the same names as packages in the standard raspbian.raspberripi.org repository specified in /etc/apt/sources.list, it could override the "real" system packages with others of its own making.
I love the "overly paranoid" label, when you're talking about a repo than can alter "real system packages".
In what world is this OK?
I think the main problem is just screwing with the system like that without permission. I mean, I know I was pretty pissed off when I found a Microsoft repo in my sources one day. It's not like it was a standard update or anything.