I agree that it feels insecure, but is there really a difference between this and downloading and running files from a .tar.gz or installing a .deb for example?
apt-get:
$ ls -l /etc/apt/trusted.gpg.d/
Source Installation: $ wget http://nmap.org/dist/sigs/nmap-6.01.tgz.asc
$ wget http://nmap.org/dist/nmap-6.01.tgz
$ gpg nmap-6.01.tgz.asc # apt-get --allow-unauthenticated ...