5
Right - there are plenty of cautions to take.
Perhaps a temporary CHMOD 777 of the modules folder could be included in the script? (I have not a lot of knowledge about permissions and what you can or cannot do from a webserver)
Also, would I want more people able to do changes to my webserver? It's not as if uploading a module folder to the root/modules and then installing it in XOOPS administration is hard.
And the "point to some tar.gz file on the Internet and run it" ... if that isn't a potential security risk, I don't know, what is

But a nice thought, nevertheless