From the README:
caveat npmtor
github's servers can be compromised by a court order, intruder, or employee.
You should use a secondary means of verification to check all the keys fetched
from github where secrecy from courts, intruders, and github employees is
of paramount importance.
This is one of the main advantages of keybase.io, though cipherhub has the advantage of not requiring users to opt-in before you can encrypt a message for them.