

You shouldn’t trust random scripts off the internet of course, but…
You do realize these scripts all come from this GitHub repo, right? It’s possible to verify them all, unless I’m missing a script here I guess. Even the registry files are plain text and readable directly in GH.





I don’t disagree that running random scripts off the internet is a bad idea, and I even made that clear. I was just pointing out that these specific scripts are verifiable entirely by the URL (which is just the raw GH file URL for the file in that repo).
I agree that signing the scripts would be a good idea though. I’m not sure how hard (or expensive) it is to do so though. If it’s anything like TLS certs, it’s probably just not worth it to them (though LE exists for TLS).