I'm not completely sure, since "Contact Request" is currently listed as TBD on the wiki, but since the JSON data is apparently limited to trusted user contacts, I assume that they have to be manually confirmed, which would limit the bandwidth of an attack. If the export also requires manual initiation (as the part about manually copying the PIN seems to suggest), this is likely not an issue.