Earlier quoted context omitted.
I wouldn't call it "shenanigans" unless there were ever a case of Mint making any change to a user's account. So far none. They're clearly not trying to trick people into giving up credentials for nefarious purposes.
I sort of agree, but to say that they can't do anything besides query if certainly false if they have the credentials that I, myself, use to log in and perform transactions. It's kinda like when Dropbox said they couldn't access user's files even though they technically could .
(Too late to edit)