Overbroad OAuth scopes are one example of this, yes. Here's another: consider all the dependencies you use in your applications as a developer. Any single one of those (perhaps hundreds of) dependencies can typically do anything you can do; it can rifle through your ~/.ssh directory looking for private keys, it can add stuff to your .bashrc, it can make arbitrary network connections, it can edit your browser settings. Likely most of them don't need to be able to do any of this. And yet that's what we accept in our computing environments, every single day.
Yes, it's incredibly dangerous.