It also has the option to upload a package.json which is far less exposure, and can easily be tweaked to omit anything sensitive.
I'm not wholly against this sort of stuff, I'm sure we've used similar links in the past for CI and coverage, but it seems to be the end of the slope, where we're handing out access to our stuff for something so frivolous. This is the same sort of mechanism that got everybody and their dog's copies of Windows XP infected with trojans in the early 2000s. "Sure, I'll install that toolbar, just let me see Britney naked".
This could be a local, auditable script that fetched a static list of projects seeking funding.