There's security consequences to allowing inline JS, which hyperscript requires.
A CSP is more valuable in a larger organization, where the codebase is always at risk of being modified by the organization's worst engineer.
>the risk from Hyperscript is not greater than any other JavaScript in the application.
This is not really the case. If all of your client-side code is loaded via <script src="..."> tags from bundles on your server, and you have a CSP that blocks unsafe-eval or unsafe-inline, then you have a pretty good barrier against execution of untrusted code on your page.