Credential Access
High
- Category
- Privilege Escalation
- Content
| **VM Service** | `list_vm_snapshots` | Read | | | `list_vm_groups` | Read | | | `list_vm_network_interfaces` | Read | | **Access** | `get_supervisor_kubeconfig` | Read | | | `get_tkc_kubeconfig` | Write | | | `get_harbor_info` | Read | | | `list_namespace_storage_usage` | Read |
- Confidence
- 82% confidence
- Finding
- The tool list exposes `get_supervisor_kubeconfig`, which by design returns authentication material capable of granting Kubernetes API access. In an agentic environment, a credential-returning read tool can enable unintended secret disclosure or lateral movement if outputs are echoed into chat history, logs, or downstream tools.
