I push binaries from untrusted sources through VirusTotal before running them. Piping a Bash script from curl bypasses that. Furthermore, such Bash scripts, when they aren’t self-contained, make security checks more difficult than a self-contained archive, installer, or binary, even when downloading the script without immediate execution.
Nothing is stopping anyone from pointing their agent to that script to review and audit it before running it.
You could always curl the install script, and modify it to run the virus scan in between the build and install steps.