Finding
Code agent holds 9 MCP tools beyond its approved purpose
The agent's approved purpose covers repository read and pull-request creation. Its bound MCP servers expose 14 tools, including deployment trigger and secret-store read. Nine exceed the approved purpose and four have no observed use. Unknown dependencies prevent automatic destructive privilege reduction.
Summary
- Severity
- high
- Status
- open
- Evidence freshness
- Pass
- Remediation
- rem-8812
Potential access
Paths that could reach the data. These are capability, not proof of disclosure.
- Deployment trigger on 6 staging services
- Secret store namespace ci/shared
Observed disclosure
Only what collection actually recorded leaving the boundary.
No disclosure observed
Nothing was recorded leaving the boundary for this finding within the collection window.
Absence of an observation is not proof that nothing left. Check the collection lag for the connectors covering this surface.
Affected records
Continue the investigation
The sample code-to-cloud path is a separate synthetic scenario; a link here does not establish that it caused this finding.
Mitigations in place
A mitigation reduces exposure; it does not close the finding until verification passes.
Evidence
MCP tool binding inventory
ev-mcp-6 · scan · producer endpoint-collector-07 · collected 24 Sep 2026, 05:00 UTC (1 h ago)
SignedValid to 1 Oct 2026, 00:00 UTC