Over-eager permissions like this are especially bad if you have access to private work repos. Github's oauth scopes are based solely on the public/private nature of the repo, no way to restrict access to a subset you'd actually like to use for a service.