I would say that the risk is very low. OpenAI has allowed usage of Codex's OAuth in other AI harnesses (as per communications on X/Twitter), and this is simply generalizing that. I have personally been using OpenAI OAuth's CLI frequently since v1 months ago.
That being said, by using OpenAI OAuth, you assume the risks of using this project, and you are still responsible for complying with OpenAI's Terms of use and usage Policies. See https://github.com/EvanZhouDev/openai-oauth#legal for more information.