This is an interesting concept. It gets me thinking: what exactly makes this "slightly evil"?
It's not actually doing anything nefarious. It checks to see if it can use your credentials to access certain sites, but it doesn't actually do anything with them besides tell you that it worked.
There is of course the potential for doing nefarious things using your credentials on other sites. But... all software which receives a username and password has that potential.
I can only conclude that it's "slightly evil" to point out the possibility.
This reminds me of something I've worried about from time to time. I have a fairly sophisticated password scheme from before there were good password managers. I don't have unique pass per site but close to it. I still forget sometimes which goes where and end up entering in real passwords just that are for other sites. There are probably a few sites at this point that have seen me enter in all my real (but wrong for that site) passwords. All some evil actor would have to do is keep a log of my attempts at one site and they could get pretty far with getting all my passwords. It's pretty scary.
If you think long and carefully enough, you'll find out "evil" is just something that would offend or harm other people.
Showing that you can log into someone else's account with info they provided you is like saying "dude, you stupid".
And even though your intention is for them to take care of themselves, they will, instinctively take that as an aggression.
Sure it's not as bad when it comes from a website, but I bet you know how people react when you try to teach them something they don't wanna learn.
Attempting to login to someone else's account without permission is clearly unauthorized use of a computer system. People have gone to jail for much less.
It's hitting a load of third party services - for its own benefit - that were never intended for that purpose.
I would hate to run a service and find some freely available script was letting anyone use it in an automated fashion. It's like what happened with the whois system and the catchas that providers had to add to prevent abuse from scripts.
It's not actually doing anything nefarious. It checks to see if it can use your credentials to access certain sites, but it doesn't actually do anything with them besides tell you that it worked.
There is of course the potential for doing nefarious things using your credentials on other sites. But... all software which receives a username and password has that potential.
I can only conclude that it's "slightly evil" to point out the possibility.