Now that nearly all URLs are HTTPS with valid certificates, the remaining risk seems to be that the host could be intentionally or unintentionally doing something destructive.
Sure it would be great to review the code of every install script before you run it, but as you allude to, it isn't practical.
Maybe something like ChatGPT could help us here?