A ServiceAccount token can do exactly what its RoleBindings and ClusterRoleBindings allow. The ServiceAccount Token Scope Checker resolves those bindings locally and shows you the aggregated permissions, so you can spot over-privileged tokens before they ship.
Paste one or more RBAC manifests. The tool maps each ServiceAccount to the Roles / ClusterRoles it is bound to, lists the apiGroups, resources and verbs it can act on, and raises risk flags for cluster-admin, wildcards and Secrets access.
Everything runs in your browser; nothing is uploaded and no cluster connection is made.