If your financial situation is not difficult, I hope you can pay by donation(even 1CNY is appreciated). If you are not willing to donate, you can consider to lend some money to me.
At first, I want to say it is ok to get any software(the apk file) from your friend. Suppose, you get this authenticity tool from your friend. After installed it, you use it to check the apk file by comparing its SHA256 value. Generally speaking, this suffices to ensure the software you got from your friend is indeed authentic.
Strictly speaking, you might be fooled: The adversary wrapped the apk file from me and produced a new apk. What you got might be the new apk from the adversary, and what you installed is the one from the adversary. The one from the adversary might be pretend to be the one from me. How to ensure this is not the case? Before you installed it, you can check how many bytes it is. If the bytes is right, then very unlikely there is any adversary who is trying to fool you.