Agent Blast Radius

io.github.makashv0.3.0Updated Oct 2, 2026

Scan what an AI agent running as you can reach; optionally verify which keys are live (x402).

VerifiedSTDIODesktop onlySecurity & MonitoringDeveloper Tools

Overview

AI-generated overview

Scans the credentials and configs an AI agent running as you could reach, and optionally verifies which keys are live for a fee.

What it does
Agent Blast Radius inspects places a coding agent running under your account can read — cloud profiles, dotfiles, project .env files, CI configs and MCP servers — and reports credential types, locations, SHA-256 fingerprints, scope hints and MCP reachability without printing secret values. It scores the exposure and can write a shareable PNG card and share text. As an MCP server it exposes blast_radius, explain_credential and blast_card, all read-only and offline, plus verify tools. The optional verify flow counts eligible findings, creates a claim with class counts only, and after payment runs checks such as aws sts get-caller-identity and provider model-list probes locally to report each…
When to use it
Use it when you want to know what secrets and configuration an agent running as you could reach, for example before granting an agent broad local access or when auditing a developer machine. The verify step is for when you need to know whether discovered credentials are actually live rather than merely present.
Requirements
Runs as a local stdio process; Node.js 22+ is needed for the npx launcher, and release binaries exist for macOS and Linux on ARM64 and AMD64. No accounts, API keys or environment variables are declared for the scan. The optional verify flow requires a crypto wallet and payment in USDC on Algorand, and network access to the provider's site.
Before you install
The scan is described as offline, read-only and never printing secret values, and it writes a PNG card and share text by default unless disabled. The verify flow is paid: $0.10 USDC per check on Algorand, paid from your own wallet, and payments are final. It sends class counts only to the provider's site, and the README states credential values, profile names, environment variable names, file paths and scan output are never sent. Release binaries are not code-signed or notarized, so verify…

Installation

In SourceWeft

  1. Open Agent Blast Radius in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

Agent Blast Radius

What could an agent running as you reach? blast scans the places a coding agent running as you can read — cloud profiles, dotfiles, project .env files, CI configs, MCP servers — and tells you what is exposed, scores it, and draws a card you can share. Offline, read-only, never prints a secret value. Optionally, blast verify checks which of those credentials are actually live, paid per check with your own wallet.

sh
npx -y @kloudle/[email protected]          # scan + share card (free, offline)npx -y @kloudle/[email protected] verify   # which keys work? (paid, optional)

More at abr.kloudle.dev.

Install it where your agent runs

WhereHow
Any terminalnpx -y @kloudle/[email protected] · brew install makash/tap/blast · curl -fsSL https://abr.kloudle.dev/install.sh | sh
Claude Code/plugin marketplace add makash/agent-blast-radius then /plugin install agent-blast-radius@kloudle
Codex (CLI and app)codex plugin marketplace add makash/agent-blast-radius then codex plugin add agent-blast-radius@kloudle
Claude DesktopDownload agent-blast-radius-0.3.0.mcpb and open it
CursorAdd to Cursor
VS CodeInstall in VS Code
Devin Desktop (Windsurf), Cline, Zed, any MCP client{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/[email protected]","mcp"]}}}
Agent Skillsnpx skills add makash/agent-blast-radius
Rules filesCursor · Devin Desktop / Windsurf · Cline

Release binaries and SHA256SUMS are on Releases: macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the checksum. The npm launcher and install.sh verify it for you. Node.js 22+ for npx.

The scan

  • Reports credential types, locations, SHA-256 fingerprints, local scope hints and configured MCP reachability. Never values.
  • Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
  • Writes a 1080 × 1350 PNG card and share text by default (--anonymous drops your username, --no-card skips files). Existing files are never overwritten.
  • Scores are exposure estimates, not proof that a credential works or was compromised.

As an MCP server (blast mcp) it offers blast_radius, explain_credential and blast_card (read-only, offline) plus the verify tools below.

Which ones are live? blast verify

The scan can't tell a dead key from a live one. blast verify:

  1. counts eligible findings (AWS profiles; OPENAI_API_KEY / ANTHROPIC_API_KEY in the environment) and creates a claim at abr.kloudle.dev with class counts only, e.g. aws-sts-identity:2;
  2. prints the price — $0.10 USDC per check on Algorand — a code, and two ways to pay with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's algorand-mcp), or a browser link where you approve in Pera, Defly or Lute;
  3. once paid, fetches an Ed25519-signed manifest, runs the checks on your machine (aws sts get-caller-identity, provider model-list probes) with a minimal environment, and reports each finding as live, rejected or error.
sh
blast verify --open            # open the pay page and waitblast verify --claim <id>      # collect later (claims survive restarts for 30 days)blast verify --list            # unfinished claims on this machine

MCP: blast_verify_quote → pay → blast_collect. Payments are final. Need a wallet? abr.kloudle.dev/wallet.

Never sent: credential values, profile names, environment variable names, file paths, scan output. See abr.kloudle.dev/privacy.

License

Proprietary — see LICENSE.txt. Free to use for checks on machines and accounts you own or are authorized to assess. Third-party notices: THIRD_PARTY_NOTICES.txt. Scanner source is private; this repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.

Source: README.md at commit 606bf33

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.3.0LatestOct 2, 2026