Install something that connects WordPress to a cloud service and you are usually asked
to grant access to everything in the account. Asking for everything is the quickest way to
build it. It also means that if the plugin is compromised, or the developer's app
registration is, whoever did it has your whole account.
Narrower options almost always exist. An app-scoped folder, a read-only token, a single
resource instead of a directory. They cost flexibility and a good deal more work. What you
get back is that a plugin with a bug in it still cannot reach anything you didn't hand it.
That is the whole product idea, and it is also why each plugin stays small. One plugin,
one job, one permission. If you want a suite that does everything, I'm not building that.