The JS code sent to kentonv's browser might be safe, but you can't really meaningfully comment on hobs' situation, since you don't have a copy of the JS code that was sent to hobs' browser.
In all seriousness, I appreciate the added context your (particularly this last clarifying comment) add to the discussion.
But if that's the case then you shouldn't click on anything on HN.
I would argue that it is A-OK to post this link directly on hackernews.
It just says "look at what your browser can do! imagine if blackhats took advantage of this."