credential-verb
A deny rule: it refuses an agent minting, printing, rotating or revoking a credential through the CLI, and names what to run instead.
What it catches
An agent minting, printing, rotating or revoking a credential through the CLI.
Why
An agent holds the token it was given, and a session that mints another holds a grant nobody handed it. Refused: the console and connector token create and revoke commands, magus graph export --open --follow (its link carries a sign-in code), and magus config token print, generate and revoke, the operator token that reaches token management. It holds however the binary is spelled: ./magus, a path, go run ./cmd/magus, or inside a $(...) substitution. This is a seatbelt for a harness that opted in, not a boundary: a process running as the user can reach the same files.
Seeing it
A verdict names its rule in brackets, which is how you got here:
deny [credential-verb]: ...
magus describe rule credential-verb prints the same entry at a terminal, and
magus describe rules lists every rule this workspace enforces.