I really dislike these "nothing to hide" takes.
It's not just "something to hide". You're giving a tiny project complete read/write access to your twitter. What if the creator abandons it and sells it to a malicious owner? What if it gets hacked? What if someone who's out to get you finds this as an attack surface?
The API separates these permissions for a reason.