download-vulnerability-list documentation insufficience

download-vulnerability-list's manpage says, for the -s switch:

     -s            Verify the signature of the current pkg-vulnerabilities
                   file.  In order for this to function correctly you will
                   need to add the pkgsrc Security Team key to your gpg
                   keyring and trust it.  The key is available from:
                   In addition to this the gpg binary must be installed on
                   your system.  The path to the gpg binary can be set in

I think it would be nice to *not* assume everyone knows how to add a key to a keyring, and give the proper command to run. What is it?

Also, the path to the file given should either be an url or host:/path.

 - Hubert

