This isn't just for local .env files. It can be quite common to need production tokens for cloud systems if you job requires any amount of ops. eg doing anything aws cli work may result in a token stored in ~/.aws
But even that aside, there's still merit in protecting rogue processes from trashing your non-production environments