No one will pay attention to the package installation comments, and I doubt many users even understand what nmap is or does.
A package won't be installed by UD unless specified in the plugin, is downloaded using a secure link, and the MD5 checksum is verified. All UD packages are hosted on my secure Github. They are not downloaded randomly from the Internet. I think you are overreacting a bit here.
I have added a parameter to the "UD Settings" that will allow you to remove the nmap package if it is that much of a problem for you. It is removed when the array is started, so you have to reboot or stop and start the array for it to take effect. nmap is installed by default when the plugin is installed.