You can run unverified code if you build it yourself. You can distribute unverified code by just paying $99/year to Apple. Not great, but still no need for specific code approval.

Not if you want to use some features like bridged networking. For that you need to go and beg Apple for an entitlement. Or you have to disable SIP entirely.

They respond to the begging as incredibly well as they respond to feedback/bug reports, right?

To be fair, they _do_ respond well in this particular case. But you have to write an email to a developer somewhere in Apple, as there is no established process.

You can run whatever scripts you want without paying anything. Pretty sure the signing thing only applies to .app programs.