Downloading a Python package (as done by scrapers, mirrors and security analysts) does not run setup.py. Only if the module is installed is this run.
It's analagous to downloading vs. running an executable.
It's analagous to downloading vs. running an executable.
It's not the case for wheels though, so you can protect yourself by restricting to binary : --only-binary.
Also doing a pip download is not sensible to this issue, but most people do pip install