Earlier quoted context omitted.
Could you explain this a bit more? How would this be more open than port forwarding? I don't see how someone could leverage this without exploiting whatever app is hosted as the hidden service?
Yes, it's exactly like port forwarding.
But with client authentification that wouldn't be a problem anyways because only chosen clients get access.