"Dark web" (lol) hackers are already going to be circulating the sources of this list and in any case could probably crack sha-1 reasonably quickly. So if you do a minimal amount of verifying the person who asks (e.g. ring their university) you can surely help the good guys with little risk of misuse?