Agent Blast Radius

io.github.makashv0.3.0更新于 Oct 2, 2026

Scan what an AI agent running as you can reach; optionally verify which keys are live (x402).

概览

AI 生成的概览

扫描以你的身份运行的 AI 代理可触及的凭据与配置,并可选付费验证哪些密钥仍然有效。

功能
Agent Blast Radius 检查以你的身份运行的编码代理可读取的位置——云配置档案、dotfiles、项目 .env 文件、CI 配置和 MCP 服务器——并报告凭据类型、位置、SHA-256 指纹、作用域提示和 MCP 可达性,且不打印任何密钥值。它会对暴露程度打分,并可生成可分享的 PNG 卡片和分享文本。作为 MCP 服务器,它提供 blast_radius、explain_credential 和 blast_card,均为只读、离线,另有验证工具。可选的 verify 流程会统计符合条件的发现项,仅以类别计数创建 claim,付费后在本地运行 aws sts get-caller-identity 和提供商模型列表探测等检查,并将每项发现报告为有效、被拒绝或错误。
适用场景
当你想知道以你的身份运行的代理能触及哪些密钥和配置时使用,例如在授予代理广泛的本地访问权限之前,或审计开发机时。verify 步骤适用于需要确认发现的凭据是否真的有效,而不仅仅是存在。
运行要求
作为本地 stdio 进程运行;npx 启动器需要 Node.js 22+,并提供 macOS 和 Linux 的 ARM64 与 AMD64 发行版二进制文件。扫描不需要账户、API 密钥或环境变量。可选的 verify 流程需要加密钱包并以 Algorand 上的 USDC 付款,且需要访问提供商网站的网络连接。
安装前请注意
扫描被描述为离线、只读且从不打印密钥值,默认会写出 PNG 卡片和分享文本,除非禁用。verify 流程是付费的:在 Algorand 上每次检查 0.10 USDC,用你自己的钱包支付,且付款不可退。它只向提供商网站发送类别计数,README 声明凭据值、配置档案名称、环境变量名称、文件路径和扫描输出从不发送。发行版二进制文件未代码签名或公证,请校验校验和。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Agent Blast Radius,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Agent Blast Radius

What could an agent running as you reach? blast scans the places a coding agent running as you can read — cloud profiles, dotfiles, project .env files, CI configs, MCP servers — and tells you what is exposed, scores it, and draws a card you can share. Offline, read-only, never prints a secret value. Optionally, blast verify checks which of those credentials are actually live, paid per check with your own wallet.

sh
npx -y @kloudle/[email protected]          # scan + share card (free, offline)npx -y @kloudle/[email protected] verify   # which keys work? (paid, optional)

More at abr.kloudle.dev.

Install it where your agent runs

WhereHow
Any terminalnpx -y @kloudle/[email protected] · brew install makash/tap/blast · curl -fsSL https://abr.kloudle.dev/install.sh | sh
Claude Code/plugin marketplace add makash/agent-blast-radius then /plugin install agent-blast-radius@kloudle
Codex (CLI and app)codex plugin marketplace add makash/agent-blast-radius then codex plugin add agent-blast-radius@kloudle
Claude DesktopDownload agent-blast-radius-0.3.0.mcpb and open it
CursorAdd to Cursor
VS CodeInstall in VS Code
Devin Desktop (Windsurf), Cline, Zed, any MCP client{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/[email protected]","mcp"]}}}
Agent Skillsnpx skills add makash/agent-blast-radius
Rules filesCursor · Devin Desktop / Windsurf · Cline

Release binaries and SHA256SUMS are on Releases: macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the checksum. The npm launcher and install.sh verify it for you. Node.js 22+ for npx.

The scan

  • Reports credential types, locations, SHA-256 fingerprints, local scope hints and configured MCP reachability. Never values.
  • Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
  • Writes a 1080 × 1350 PNG card and share text by default (--anonymous drops your username, --no-card skips files). Existing files are never overwritten.
  • Scores are exposure estimates, not proof that a credential works or was compromised.

As an MCP server (blast mcp) it offers blast_radius, explain_credential and blast_card (read-only, offline) plus the verify tools below.

Which ones are live? blast verify

The scan can't tell a dead key from a live one. blast verify:

  1. counts eligible findings (AWS profiles; OPENAI_API_KEY / ANTHROPIC_API_KEY in the environment) and creates a claim at abr.kloudle.dev with class counts only, e.g. aws-sts-identity:2;
  2. prints the price — $0.10 USDC per check on Algorand — a code, and two ways to pay with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's algorand-mcp), or a browser link where you approve in Pera, Defly or Lute;
  3. once paid, fetches an Ed25519-signed manifest, runs the checks on your machine (aws sts get-caller-identity, provider model-list probes) with a minimal environment, and reports each finding as live, rejected or error.
sh
blast verify --open            # open the pay page and waitblast verify --claim <id>      # collect later (claims survive restarts for 30 days)blast verify --list            # unfinished claims on this machine

MCP: blast_verify_quote → pay → blast_collect. Payments are final. Need a wallet? abr.kloudle.dev/wallet.

Never sent: credential values, profile names, environment variable names, file paths, scan output. See abr.kloudle.dev/privacy.

License

Proprietary — see LICENSE.txt. Free to use for checks on machines and accounts you own or are authorized to assess. Third-party notices: THIRD_PARTY_NOTICES.txt. Scanner source is private; this repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.

来源:README.md,提交 606bf33

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.3.0最新Oct 2, 2026