The really dangerous thing is copy/pasting from a browser to your terminal. Always do Ctrl-X Ctrl-E to open an editor, paste it in there, then inspect it before saving/closing the editor to run the command.
The really dangerous thing is copy/pasting from a browser to your terminal. Always do Ctrl-X Ctrl-E to open an editor, paste it in there, then inspect it before saving/closing the editor to run the command.
The two things you need to be able to say you trust are your CA store, and the source of your curl -> shell.
There is no practical difference. "Nobody" will inspect the man page using a different viewer first. So if I download to disk and then view via man or directly via man is no difference.
A shell script one might inspect first using some viewer. While only few probably do.
For zsh users see here: https://nuclearsquid.com/writings/edit-long-commands/
Note: this can be tricky depending on where it goes in your zshrc. If you use a plugin manager (like Sheldon) then this should be above that. I ended up with this and it works well on OSX and linux
autoload -U edit-command-line
# Emacs style (<C-x><C-e>)
zle -N edit-command-line
# make sure `set -o vi` is above this line
bindkey '^xe' edit-command-line
bindkey '^x^e' edit-command-line
# (VIM) Use visual mode
bindkey -M vicmd v edit-command-line