I was tempted to expand that with "without pasting a malicious command in it", with Discord users being tricked into doing this in their Chrome console as the example.
However, most of HN is curl-bashing unverified scripts into their computers and servers...
PS: shout-out and thanks to ben_w who mentioned this article in the discussion about the Algerian internet shutdowns.