please stop piping into bash or sh. force people to use the editor, read the install script, and tell them how to run it
Not saying you shouldn't check your scripts, I usually do, I like to know where the files are going in case the installer messes up, but the risks tend to be overstated compared to running the executable itself.
what's left is adding the init command to the shell init script.
and it turns out that this is included as an alternate way to install in the repo README.
i really don't see the point of the install script. the verification it offers is of no value because if the repo is compromised then the install script could be compromised too.
It's more realistic to decide if you trust the source, GitHub user yamafaktory in this case. Then you can ensure that your method of download uses TLS.