I'm sure Google is not using http://googledrive.com/ for anything that's user-identifiable.
The only harm that I think can happen with JS is you being able to access/set any cookies/storage that are set by another 'public' site hosted on Google Drive that you've accessed earlier.
Looks like 20GB (free) or 200GB (paid) per day.
If you need more bandwidth, you would probably be looking at any of the other innumerable hosting solutions available on the web.
Look at the screenshot in the article. It is in fact using https://googledrive.com/
The threat is that a user logs in to googledrive.com and receives an authentication cookie tied to their Google account. Later, they view a malicious user page at googledrive.com/host/someevilpage, and a script on that page reads the authentication cookie and sends it to the attacker, who can now log in to googledrive.com as the victim.
That doesn't happen here because you don't actually log in to googledrive.com. The worst a malicious script could do is harvest data set by other scripts, and that's a drastically smaller (although still present) threat.