Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243 but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits
Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.
Unfortunately, I’m not aware if they did external audits, but both codes are available in github.
At a user level, the biggest security compromise with signal is enabling notifications