While I understand the argument you're making, the exposure of running "curl | bash" on your local machine is much higher than running arbitrary code inside of a container.
Even if you specify a hash, are you actually checking all of the code and binaries in that image?
What about the image base (e.g. Alpine, Debian) and their packages?