Who controls your client has access to your inbox with most services even the few that have separate IMAP/POP3 passwords like Hushmail can be compromised through it.
If your client also integrates with encryption or worse takes charge of it my encryption key is also now at risk.
Lastly since email today is pure HTML you also inherit all the possible vulnerabilities that come with having a DOM parser and a layout engine and even modem browsers still get both wrong.
And using something like Electron or even Chromium won’t implicitly save you because the way you implement them matters a lot and now you are tied with their update cycle which might break functionality forcing you to manually backport security fixes which is hard to accomplish.
So unless you have the source or show an audit from a respected firm (c53, isec etc.) its going to be quite hard to recommend to anyone to take the dive and try this out.