Package commands execute code with your permissions.
Running an unfamiliar package can expose your files, environment variables, network, and shell before you know what the package intends to do. The usual install prompt gives you almost no useful context.