Pretty sure it always autosaved so this makes sense to me? I always assume it would send my data over to their backend, its code that ends up there regardless?
Edit: The point is that any secrets typed/pasted in there should be considered compromized
That flow would be considered unsafe, and probably common.