That's the major problem with these scripts, you rely on the web server not having been compromised, the release builder not having been compromised and you not being MITMed. Now, someone might inject nasty changes into a code repository, but it tends to be harder.
That's just one of the problems, but I'd say it's the main one. If you truly trust the creator with install power, download the script yourself with curl/wget/whatever, have a glance if it's what you expect, and fire away.