It's also a matter of UX. Github (or anyone with social login) should be clear about what your granting. "Do you trust this website? They will be able star repos on your behalf"
... "and if they do this too often, it's your account that will be punished" (in big bold red text and with a 15 second delay before the authorize button is enabled).
For example, these two prompts look very similar:
https://community.atlassian.com/t5/image/serverpage/image-id...
https://user-images.githubusercontent.com/2584493/51578239-b...
But they have entirely different levels of access!
What you're doing is victim blaming. The phishing/scamming equivalent of shouldn't have been walking down an abandoned street at 1am in the morning.
If anything, Github already wasted time by targeted the user into a victim, rather than the original source of the API call.
Punish the site. But dont bother wasting anymore resources to protect the stupids. Its their own action, let them be accountable for their own choice.