Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The script requests broad "read write" OAuth scopes for a helper that is described as a NeoDB assistant, without any evidence of scope minimization or per-operation consent. Excessive scopes increase blast radius: if the token is exposed, an attacker can perform any API actions allowed by both read and write access rather than only the minimum needed for the intended workflows.
