It is certainly an interesting concept. It can be used as an "offline signer" in conjunction with Electrum... so instead of using a 2nd computer, you simply transfer the unsigned transaction to your coldcard via a microSD, sign it, then transfer it back to your online PC and broadcast.
However, my concern lies with the fact that the microSD can also be used to "update firmware"...
and "backup your (encrypted) seed".
I wonder how long before someone figures out a way to update the firmware so that it creates an
unencrypted backup of your seed on the microSD card

I have tried the backup option. It creates a 12 word mnemonic that acts as the pass phrase to decrypt it.