Does it also terrify you when code running in a browser does it?
"web browsers already do this ;)" isn't a good comparison.
Actually, no Deno webserver I've written gets fs access. Some only get --allow-net.
Here is the page with more detail. https://deno.land/manual/getting_started/permissions
It can even restrict access down to a specific directory or host. This is cool.
Whereas any NPM module can map your subnet, lift your .ssh directory, and yoink environment variables, wily-nily.
It's happened before.
It'd be nice to have some capability model where modules can only access things through handles passed to them, but probably infeasible for a project like this.