the only workaround is to install a custom ROM without google play and google services
That’s overkill, with a rooted phone you can simply freeze (might be able to freeze it with ADB as well) or delete the Play store (it’s the Play Store where this Malware lives). GMS and Account Manager will work just fine without the Play store.
Or, like the other person said you can just disable Play Protect.
Is there any evidence that this will really remove Google’s ability to (a) see what’s on your phone, and (b) delete whatever they want?
No, since on GrapheneOS Google Play Store/Services doesn’t have permission to silently install/uninstall apps. They are sandboxed like any other app (i.e. F-Droid).