If someone being able to download your source code repository is opening yourself up to attacks, you're doing something wrong. Either you are relying on security through obscurity, or you checked keys into git. Both horrible practices.
I would do it, if I was certain I could avoid accidentally publishing the repo. I'd never describe it as 'bad', as that's extremist & it's easy for someone who does this to misinterpret you as saying, "you are bad for doing this and not following best practices".