Yes, the author was testing with a reflected XSS attack string, and yes "there should be no case of concern for DoS". But that's exactly my point. You have no idea what effect that will have.
I personally have caused an inadvertent DoS attack with an XSS probe while doing a security audit for a large SaaS company. (The attack made the code throw and exception and some of my escaping characters caused havoc with their error logger, sending it into a infinite loop trying to log data, pegging the CPU and growing memory until the disk thrashed.)
You don't know what you actions will cause because the server/app is a black box. And if you want to audit that, you should have a formal agreement with the company that they know what you are doing and its OK. A generic, flimsy, non-personal "everyone can try and 'hack' us and it's OK" policy published somewhere is just too little protection, especially given how the CFAA is applied in courts today.