Primal's NIP-05 verification service works like any other Nostr NIP-05 verification service. All Primal clients verify NIP-05s on the client; same way as other Nostr clients. That's why Primal clients don't show the verified badge next to the account that tries to spoof the NIP-05. The indexer plays no role in the display of the verified status in our clients.
So you got this entirely wrong. The "architectural vulnerability" you point out is a hallucination by your LLM. Run this by your LLM and post the screenshot of its apologies for the lols.