Skip to content

explain <agent>: state effective capability by joining logged-in CLIs to the agent's shell (section 23) #83

Description

@moise10r

The situation

Section 23 of VISION.md: AWS credentials, kubectl, a production kubeconfig, network access and a shell together mean "can modify production Kubernetes". Today the pieces exist separately:

  • authenticatedClis and productionLooking in packages/core/src/discovery/credentials.ts:210-275 are machine-wide.
  • packages/core/src/discovery/reachability.ts gives each agent viaShell.
  • discovery/composition.ts only chains MCP tools.
  • packages/cli/src/commands/explain/agent.ts:127-146 prints "shell: holds one, which reaches everything you can", and nothing about which CLIs that shell can drive.

Suggested approach

A pure function effectiveCapabilities(agent, reachability, authenticatedClis, policy) in core/discovery, rendered in explain <agent> and in the scan's per-agent section, producing lines like: "claude-code can run kubectl against context prod-eu-1 (named like production): 12 destructive verbs". A policy or OS guard that denies the credential file, or restricted network, marks the finding governed.

Acceptance criteria

  • Table tests: shell plus a kube credential gives a finding; no shell gives none; a denied credential file gives a finding marked governed.
  • The "named like production" wording is kept, never "production".
  • Counts, never scores.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions