Aren't they? Are you sure piping to 'man' can't result in arbitrary code execution?
The two things you need to be able to say you trust are your CA store, and the source of your curl -> shell.
The two things you need to be able to say you trust are your CA store, and the source of your curl -> shell.
There is no practical difference. "Nobody" will inspect the man page using a different viewer first. So if I download to disk and then view via man or directly via man is no difference.
A shell script one might inspect first using some viewer. While only few probably do.