What makes it secure? (There's no readme, and it just links to GrapheneOS homepage.)

https://grapheneos.org/usage#grapheneos-camera-app

By default, doesn't save metadata to images.

Always saves metadata to videos.

Doesn't request or need media/storage permissions. Defaults to no location permissions.

So good - but room for improvement?

Additionally all grapheneOS built in apps are going to be as compliant as possible with all of the app sandboxing and hardening features. Like mte, dcl, etc.