It is just not wise to allow some random application to MiTM your SSL traffic.
If you can read the code and asure that the traffic won’t be sent to a malicious third party, why not? What is the concern?
You don't know this person, and I see no personally identifiable information to make me trust them. They could literally be a state actor right now! We've also seen so many large supply-chain attacks over the last decade which could easily target a tiny project like this.
I agree with the parent - not wise.