Nice idea. Can you reduce the permissions required?
> This application will be able to read and write all public and private repository data. This includes the following:
Can it just be access to that one repo?
> This application will be able to read and write all public and private repository data. This includes the following:
Can it just be access to that one repo?
But even if they weren't, in general you want to assume you will be hacked, and then based what permissions you ask for based on that assumption. I.e. be secure, and use principle of least priveledge, even if the users don't care. This is why I try to get out of having admin permissions to things at work :-) </rant>
A lot of IoT security problems has that combo of vendor and consumer both not caring/understanding/being aware of security issues.