This is a really good point. There was another post recently linking to a search for id_rsa files (SSH private keys) on GitHub. Instead of allowing people to publish sensitive things like that accidentally, GitHub really should require an extra confirmation.