upvote
You could always curl the install script, and modify it to run the virus scan in between the build and install steps.
reply
Nothing is stopping anyone from pointing their agent to that script to review and audit it before running it.
reply
I don’t believe an agent can do that effectively without a sandbox to run the script in, if the script isn’t self-contained.

And everyone running a research agent on every download can’t be the solution. It’s much more effective to crowdsource a security database based on hashes. But for that, the downloads need to be self-contained.

reply