Curious, what would be an ideal (secure) approach for you to install this (or similar) tool?
I'm not arguing that a repository is nice because versioning, signing, version yanking, etc, and I do agree that the process should be more transparent and verifiable for people who care about it.
The alternative is, deploying the script and with it have the uncloud files it needs.