I don't think the fear is that they'll steal code you'll end putting publicly on GitHub, but everything else. I guess there is some fear that it won't just analyze and process what you currently have open, but might scrape your computer for more data and so on.
I personally don't believe ByteDance would be stupid enough to even attempt exfiltrating files from developers machines, which typically are better protected than the average user computer, just trying to see the perspective of others with a more charitable reading :)