tbh its somewhat trivial to add support for zip's weak password-based encryption. I can enable it by default and get it to assume the password is 'thisispublic' if you want, if you want a different password, I'm sure you can set an appropriately named cvar in your default.cfg (inside the same zip if you want - its per-file rather than per zip, so just make sure your default.cfg isn't encrypted). of course, if they someone finds a zip that they can only read one file of, they're probably going to read it looking for a password - especially if its a cfg.
it really won't get you anything of course (hence the choice of default password), but when so much of game design appears to be social engineering it hardly seems to matter.
besides, features are features!