Your application's predefined Search-Only API key includes three ACLs by default: search, listIndexes, settings.
This allow the key to discover which indexes exist and read index configurations in order to allow for a more flexible / performant front-end implementation. These are read-only capabilities.
This is the behavior of the predefined key, but if you have concerns about using a search key in production with listIndexes and/or settings, you are not required to use this key.
Though the ACLs of the predefined key cannot be modified, your team can create a new API key at any time that is limited to only the search ACL and has any other desired restrictions. You would then use this key in the front-end implementation instead of the predefined key.