I'm sure the creator of the card is a fine guy, and the short time it'd be inserted along with him standing right there and your active attention means it's practically pretty safe.
The party line in security is that once an attacker has physical access to the computer compromise is so trivial mitigating any specific attack is a waste of time. That's certainly true right now: firewire, PCI-E and hard drive removal are much more dangerous. But it's more of a philosophy than a logical truth - security is really just the practice of raising the bar enough to counter the level of threat. The fact that critical computers aren't connected to the internet or any network at all doesn't stop OS vendors from spending countless hours fixing exploits.
Someday a bus design like this will seem hopelessly niave and be long gone just like telnet and analog cell phones. Virtually all attacks right now involve holes with well defined solutions - think 802.1x, DNSSEC, http and smart cards. But adoption is usually glacial and universal adoption would only lead to new holes being exploited.
The potential for USB attacks goes far beyond a simple HID controller. Any serious attacker would disguise or hide a device in a way that would make it easy to include a few more chips and a much more sophisticated design. Include a benign real device that matches whatever function the user expects - flash drive, mouse, etc. Wait some time before attaching the keyboard service suspicion - at the same time connect a serial class as well allowing a reliable command channel after just "typing" a two or three line script. Send over a better native command program, maybe wait until the user idles, mount storage or replace existing flash blocks with privesc exploits, rootkits, etc. A modern, well administered system may be difficult to exploit directly as a user. Crash or reboot the OS, possibly including a crash dump or hybrid sleep first for later access to kernel data. Once the usb bus resets, provide a variety of usb storage types for the BIOS to find - one will usually preempt the main hdd with a linux image that would show an OS appropriate boot animation perhaps with a filesystem check to explain any delay. At this point it could grab the BIOS image and repack it with a ROM root kit and reflash it or replace ethernet, video or dvd firmware to provide pre-boot or even pre-BIOS control. Attack the boot loader, kernel files or anything else needed to remove code signing requirements or install new certificates, integrity checks, install a good rootkit, etc. Disable the usb storage, pass control to the real boot loader and once full control is confirmed wipe the bad bits of NAND and microcontroller flash, blow an efuse to disable any naughty hardware and you're done.
While that is all highly speculative and sounds complex, it's 100% possible and would be a small amount of work compared to what goes into modern root kits and bot code.
Such an attack is probably not something a common user would ever face though high value targets are often subjected to at least as much effort. All bets are off if someone designed an easy to use version, produced a significant run of them and packaged them nicely. Rootkits have gone from rare and amateur to polished and plug and play and widely used rather quickly.
This spring I was shown a keyboard that included a hardware keylogger with flash, usb serial interface, a tiny microphone and a cmos clock. The chips were on a board identical in size and location of the one normally installed. It was flipped upside down, screw heads stripped clean and glued in, with a number of large industrial staples attaching it to the plastic below. When disassembled the components were found to be covered with thick epoxy. At some point during the initial investigation a trace to a small battery was broken and a SIM was destroyed. The bootstrap passed some code through the smart card and a majority of the controller and secondary flash were encrypted.
As interesting as the design was, even many dead simple gadgets require more technical expertise to create. I was told that the design was very similar to a popular commercially available keylogger minus the smart card and mic. You can find them for $100 or less many spots on the web.
The most striking fact is that the victim purchased the keyboard themselves from a well known US web store as an OEM keyboard. It was delivered to his door by UPS, it was the style ordered, shrink wrapped, and included another item that was legit. Suspicion arose because the keyboard quality was low and appeared counterfeit. When connected, it displayed a device name that included some unicode and some garbage at the end that included some simple shell code.
The user didn't know why he'd been targeted and lacked any typical high risk factors or usual motivations for attack. The source was never identified, no similar kit was found in the retailer's stock. The item had sat in the users wish list at the retailer for several months before being ordered. The victim reported a sophisticated attack occurring nine months prior, no evidence was found of an existing intrusion. Law enforcement suspected it had been included accidentally before leaving china and likely is produced on the same line as benign versions.