Earlier quoted context omitted.
This also serves as a reminder that code hosted on github might be malicious and we shouldn't blindly trust those just because the author seems to have similar interests.. I've done that multiple times :(
Yes. Remember that not only security researchers but also developers in general are extra juicy targets because of e.g. their AWS credentials that sometimes aren't kept as secure as they need to be. Heck, even if you're doing proper SSO with 2FA the tokens can be stolen and data proxied/exfiltrated. At best they can be used for coin mining (running up a huge bill), at worst for stealing private customer data (and the…
There is some irony in there.