Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
If you've already decided you trust the author, what's the actual threat here?
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
program.bin
install.sh
It seems rather pointless for me to thoroughly inspect the install script before I run the program.