The Zapier people are probably decent and honest etc, however that's not the point. It introduces a new security threat and attack vectors unnecessarily
It violates the principle of needing just enough access, to perform a task.
To expand on that Mint never stores your account passwords. Yodlee does and provides the data back to Mint. Here are their security claims: http://www.yodlee.com/security.html
As one data point, my credit union specifically recognizes accesses to my account from Yodlee, due to my Mint usage.
That you don't isn't really an argument for them changing their practices.
For example Mint.com keeps your banking passwords in order to do offline-logins, but people still trust Mint not to steal their money.
If many people don't trust a startup, I think they likely need to change their presentation style and not their practices.