I suppose /usr/sbin/nologin is not a thing?
It does not stop you from, say, logging in to SSH and then starting a port forward. Or running a command in a way that bypasses the login shell. ssh will always pass it to your login shell but other ways can be vulnerable.
[1] - sftp ai@nochan.net