So I’m basically an idiot when it comes to this type of thing…but can a person/corp/alliance do anything nefarious with the following:
esi-fleets.write_fleet.v1
esi-ui.write_waypoint.v1
esi-characters.write_contacts.v1
esi-fittings.write_fittings.v1
esi-corporations.write_structures.v1
Fleet writing allows them to manage a fleet you happen to be in a leadership position of. Waypoints can only troll your route stuff (changes will turn off AP). Contacts can be used to modify someone’s standings with you. Fittings… other than deleting your fittings (which you should periodically back up to a file to begin with anyways), not really. Structure writing? Possibly. Havent bothered with corporate/structure stuff myself.
Just bear in mind, if you think something hinky’s going on, contact CCP with a timeframe of when it happened, and a list of apps you have authorized (and their scopes). They’ll be able to track down what api requests were made and deal with the owner of the app.