However, decoding and verifying a complex transaction takes about the same amount of work as generating it yourself to begin with...
Their documentation clearly expects you to blindly sign whatever tx they make up for you. There's not a word on verifying the transaction locally before signing it.