The situation
Section 23 of VISION.md: AWS credentials, kubectl, a production kubeconfig, network access and a shell together mean "can modify production Kubernetes". Today the pieces exist separately:
authenticatedClis and productionLooking in packages/core/src/discovery/credentials.ts:210-275 are machine-wide.
packages/core/src/discovery/reachability.ts gives each agent viaShell.
discovery/composition.ts only chains MCP tools.
packages/cli/src/commands/explain/agent.ts:127-146 prints "shell: holds one, which reaches everything you can", and nothing about which CLIs that shell can drive.
Suggested approach
A pure function effectiveCapabilities(agent, reachability, authenticatedClis, policy) in core/discovery, rendered in explain <agent> and in the scan's per-agent section, producing lines like: "claude-code can run kubectl against context prod-eu-1 (named like production): 12 destructive verbs". A policy or OS guard that denies the credential file, or restricted network, marks the finding governed.
Acceptance criteria
The situation
Section 23 of
VISION.md: AWS credentials, kubectl, a production kubeconfig, network access and a shell together mean "can modify production Kubernetes". Today the pieces exist separately:authenticatedClisandproductionLookinginpackages/core/src/discovery/credentials.ts:210-275are machine-wide.packages/core/src/discovery/reachability.tsgives each agentviaShell.discovery/composition.tsonly chains MCP tools.packages/cli/src/commands/explain/agent.ts:127-146prints "shell: holds one, which reaches everything you can", and nothing about which CLIs that shell can drive.Suggested approach
A pure function
effectiveCapabilities(agent, reachability, authenticatedClis, policy)incore/discovery, rendered inexplain <agent>and in the scan's per-agent section, producing lines like: "claude-code can runkubectlagainst contextprod-eu-1(named like production): 12 destructive verbs". A policy or OS guard that denies the credential file, or restricted network, marks the finding governed.Acceptance criteria