It's all about trust.
When you run:
apt-get install foo
is it any different? You download a file that essentially runs anything pre- and post- install of the rpm.