Yeah, that's great!

Imagine we would download random code from the internet and just execute it, like with NPM, PIP, Maven, Cargo etc.

cargo/uv/go have lock files though

with curl | sh you could use a checksum you download with curl!