Currently the account linked is not suffice to secure the request, I mean is not standard to obtain an access token under user A but the invocation is done with user B.
What I would like to see is:
- Installing an skill that requires account link will ask each household interested in the skill to authenticated with the skill identity provider, this mean that alexa service will have a set of tokens per household per skill.