You’re right on the dangers of an error in the updater script being a single point of failure and it could propagate to all users. As a side note, the code is on GitHub, so updates could be rolled back in case of some (unlikely) critical error in the ostree script itself.
That being said, one could argue that the whole system (base image) has the same Achilles’ heel. All the system images are the same, so a bad image is going to be bad news for the whole community. 
Given how easy it is to revert changes/updates, I would be pretty relaxed about this possibility. Plus, the devs are awesome at what they’re doing with Fedora in general, so there’s this, too. 