IME most of the randomly-downloaded software I've used does what it says on the tin. But there is a whole screening process: where did it come from? Does the originating site look legit? What are the possible motivations for the creator?
Besides there is no signing mechanism for your random install.sh. Maybe you check the SHA256 but if an attacker alters the script why not alter the website with the hashes too?
``` curl -sfL https://get.k3s.io | sh - ```
- Not everyone is proficient in bash.
- Some install scripts can easily go on for thousands of lines, especially if they are designed to work with multiple distro or architecture, or both.
- Said install script might be integrated deep down into someone else's build pipeline.
- ... that's assuming they aren't the type that would blindly download and run random exe from the web in the first place
Pretty common, I would say.