Earlier quoted context omitted.
How? It's over HTTPS, and you're already trusting them to execute code on your system... and it's not even root... I see no way in which this "leaves your computer at their mercy" more than any other process of purposefully executing code they control on your system.
this seems like a 'perfect is the enemy of good' framing. in any event, it's more surface area. their web server being compromised and serving a bad shell script is just more that can go wrong.
If they were serving up a binary you would have the same exact threat that you mentioned.
The threat model barely, barely changes when talking about curl | sh vs downloading and manually executing a binary. Barely.