but people pipes a shell script from a URL to bash all the time. with enough practices, it becames second nature.
For that matter, there's always a risk of downloading/installing anything from anywhere. There have been successful compromises of many application supply chains at this point in official release paths. You will accept some risk regardless of your approach.