Before SSL certs were as ubiquitous as they are now, we used to warn about the danger of curl to bash for unsecured URLs, as it's a vector for a DNS spoofing attack.
Now that nearly all URLs are HTTPS with valid certificates, the remaining risk seems to be that the host could be intentionally or unintentionally doing something destructive.
Sure it would be great to review the code of every install script before you run it, but as you allude to, it isn't practical.
Maybe something like ChatGPT could help us here?