Properly implemented, NFC auth provides a secure challenge-response mechanism with a private key, so mirroring would not be possible.
Theft is a potential problem, but so is shoulder-surfing. At least if your auth token goes missing then you know you've been compromised.