In various venues, the question has come up a number of times of whether and how Solid prevents apps from using data for unintended uses, notably exfiltrating data in a way that then allows arbitrary access for any use.
I've titled this as an attack consequence because it's currently trivial - any app authorized to read data can exfiltrate it. However, it is still something we don't want, and it is something that might be mitigated in future.