Both are a security nightmare, if you're not verifying the signature.
You should verify the signature of all things you download before running it. Be it a bash script or a .deb file or a .AppImage or to-be-compiled sourcecode.
Best thing is to just use your Repo's package manager. Apt will not run anything that isn't properly signed by a package team members release PGP key.