That looks like an easy way to get your coin base account hacked!

Not really. The app asks for permissions to buy and sell BTC. That's it.
The access tokens are stored encrypted.
Even if I decrypted them and put them publicly online, attacker would still need another key stored elsewhere to use the tokens.
The only risk is that I will go crazy one day and start buying and selling coins on your account for fun.