I can't be the only person who hates install instructions like 'curl -L some.host|bash'. Not to mention that the yeoman install script happily installs homebrew using 'curl -k ... |ruby'. No thanks.
For the people that want to check out the script:
https://raw.github.com/yeoman/yeoman/master/setup/install.sh
It's obviously a concern that you are downloading unchecked code from the internet and running it on your computer, but if you are talented enough to be able to inspect the code and certify it is not malicious, you are also talented enough how to get the code without executing it.
You're running code you haven't read. It all reduces to exactly the same vulnerability.
Do you think piping a shell script is less secure?