We need a refresh token to monitor character ownership but don't need any scopes explicitly. publicData provides no private information but grants a refresh token.
https://github.com/ccpgames/sso-issues/issues/17
Rumor has it this scope isn't going away with CREST.
adarnauth-esi will automatically create a new scope model when it encounters one it doesn't recognize.