am I correct in feeling wary of using this from a security standpoint
I don’t really think you have to be worried about security. Without an official API I’d be more worried about stability and potential data loss due to e.g. bugs in the encryption implementation or unexpected API changes though.
this is asking you to put in your Proton username and password and 2FA and it gets stored as a token in the config file.
As far as I can tell it’s just using your username and password to obtain an access token just like any other Proton Drive client, including the offical one, would have to do.
To save you a click (although none of the other commenters seem to have read the article anyway): The microchips aren’t embedded into the actual cheese that you eat, but are part of the label attached to the outside rind. Nobody will be eating microchips.