RSR Sec 4 talks about how "A malicious resource server could register a bad icon URI at an authorization server, "infecting" the authorization server either when the icon is retrieved or by confusing a human resource owner about the nature of the resource set being protected." However, the same is true for a scope or resource set name, not just an icon_uri. This should be mentioned as well.