Ah yes, run this random shell script hosted on the internet.
And I got downvoted for suggesting that they use an ML tool like crowdstrike to scan submissions for weird things.... and for some reason people pointed out that they caused one incident of linux crashes and one incident of windows crashes last year. What if I told you that you could run a scan like that on a VM with the storage, web hosting and everything else entirely separate from said scanning VM... but no, random shell scripts into terminal GO!
Just seeing the results of a sandbox detonation should give you some level of an idea that something is bad or not bad. This kind of tooling isn't exclusive to any one entity and the results should be part of any repo for anyone to review and flag if you really want to avoid ML as a layer of defense.