I never used shim - so I don’t know
You can enable secure boot without using AUR
See → [root tip] [How To] Manjaro and Windows - using Secure Boot and repo only
More information
See → Unified Extensible Firmware Interface/Secure Boot - ArchWiki
See → Unified kernel image - ArchWiki
See → GitHub - Foxboron/sbctl: 💻 🔑 Secure Boot key manager
See → Multiple UKIs with mkinitcpio? - #5 by linux-aarhus