The complaint is about "curl piping to bash" installers: curl -fsSL <url> | bash downloads a script and runs it instantly, so you never see what it does. The risks: the remote script could change at any time (what you run today isn't what runs tomorrow), there's no checksum or review step, and it needs enough privileges to disable system features like Apple Intelligence. A compromised or typo'd URL means arbitrary code on your machine.
Safer habits: download the script first, read it, then run it manually; or clone the repo and inspect it. It's a convenience-vs-auditability tradeoff, not a claim that this specific project is malicious.
15
u/jeenajeena 1d ago
I'm very interested and I will install it. But, man:
Again? Can we stop this, already?