You could always inspect the changes to see what they would have put in it, so IMO they won't make that mistake because it will make them accountable of any malware, rootkit or whatever. In fact it would be much better if they actually did just that.
Re: checking the signed binary