You're revoking the attacker's key (that they're using to upload the docs to their own account), this is probably the best option available.
Obviously you have better methods to revoke your own keys.
Obviously you have better methods to revoke your own keys.
agreed it shouldn't be used to revoke non-malicious/your own keys