Agent Blast Radius

io.github.makashv0.3.0更新於 Oct 2, 2026

Scan what an AI agent running as you can reach; optionally verify which keys are live (x402).

概覽

AI 產生的概覽

掃描以你的身分執行的 AI 代理可觸及的憑證與設定,並可選擇付費驗證哪些金鑰仍然有效。

功能
Agent Blast Radius 檢查以你的身分執行的編碼代理可讀取的位置——雲端設定設定檔、dotfiles、專案 .env 檔案、CI 設定和 MCP 伺服器——並回報憑證類型、位置、SHA-256 指紋、作用域提示和 MCP 可達性,且不列印任何祕密值。它會為暴露程度評分,並可產生可分享的 PNG 卡片和分享文字。作為 MCP 伺服器,它提供 blast_radius、explain_credential 和 blast_card,皆為唯讀、離線,另有驗證工具。可選的 verify 流程會統計符合條件的發現項目,僅以類別計數建立 claim,付費後在本機執行 aws sts get-caller-identity 和供應商模型清單探測等檢查,並將每項發現回報為有效、被拒絕或錯誤。
適用情境
當你想知道以你的身分執行的代理能觸及哪些祕密和設定時使用,例如在授予代理廣泛的本機存取權之前,或稽核開發機器時。verify 步驟適用於需要確認發現的憑證是否真的有效,而不只是存在。
執行需求
以本機 stdio 程序執行;npx 啟動器需要 Node.js 22+,並提供 macOS 和 Linux 的 ARM64 與 AMD64 發行版二進位檔。掃描不需要帳號、API 金鑰或環境變數。可選的 verify 流程需要加密錢包並以 Algorand 上的 USDC 付款,且需要連線至供應商網站的網路存取。
安裝前請注意
掃描被描述為離線、唯讀且從不列印祕密值,預設會寫出 PNG 卡片和分享文字,除非停用。verify 流程是付費的:在 Algorand 上每次檢查 0.10 USDC,用你自己的錢包支付,且付款不可退。它只向供應商網站傳送類別計數,README 聲明憑證值、設定設定檔名稱、環境變數名稱、檔案路徑和掃描輸出從不傳送。發行版二進位檔未經程式碼簽署或公證,請驗證校驗和。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Agent Blast Radius,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Agent Blast Radius

What could an agent running as you reach? blast scans the places a coding agent running as you can read — cloud profiles, dotfiles, project .env files, CI configs, MCP servers — and tells you what is exposed, scores it, and draws a card you can share. Offline, read-only, never prints a secret value. Optionally, blast verify checks which of those credentials are actually live, paid per check with your own wallet.

sh
npx -y @kloudle/[email protected]          # scan + share card (free, offline)npx -y @kloudle/[email protected] verify   # which keys work? (paid, optional)

More at abr.kloudle.dev.

Install it where your agent runs

WhereHow
Any terminalnpx -y @kloudle/[email protected] · brew install makash/tap/blast · curl -fsSL https://abr.kloudle.dev/install.sh | sh
Claude Code/plugin marketplace add makash/agent-blast-radius then /plugin install agent-blast-radius@kloudle
Codex (CLI and app)codex plugin marketplace add makash/agent-blast-radius then codex plugin add agent-blast-radius@kloudle
Claude DesktopDownload agent-blast-radius-0.3.0.mcpb and open it
CursorAdd to Cursor
VS CodeInstall in VS Code
Devin Desktop (Windsurf), Cline, Zed, any MCP client{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/[email protected]","mcp"]}}}
Agent Skillsnpx skills add makash/agent-blast-radius
Rules filesCursor · Devin Desktop / Windsurf · Cline

Release binaries and SHA256SUMS are on Releases: macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the checksum. The npm launcher and install.sh verify it for you. Node.js 22+ for npx.

The scan

  • Reports credential types, locations, SHA-256 fingerprints, local scope hints and configured MCP reachability. Never values.
  • Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
  • Writes a 1080 × 1350 PNG card and share text by default (--anonymous drops your username, --no-card skips files). Existing files are never overwritten.
  • Scores are exposure estimates, not proof that a credential works or was compromised.

As an MCP server (blast mcp) it offers blast_radius, explain_credential and blast_card (read-only, offline) plus the verify tools below.

Which ones are live? blast verify

The scan can't tell a dead key from a live one. blast verify:

  1. counts eligible findings (AWS profiles; OPENAI_API_KEY / ANTHROPIC_API_KEY in the environment) and creates a claim at abr.kloudle.dev with class counts only, e.g. aws-sts-identity:2;
  2. prints the price — $0.10 USDC per check on Algorand — a code, and two ways to pay with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's algorand-mcp), or a browser link where you approve in Pera, Defly or Lute;
  3. once paid, fetches an Ed25519-signed manifest, runs the checks on your machine (aws sts get-caller-identity, provider model-list probes) with a minimal environment, and reports each finding as live, rejected or error.
sh
blast verify --open            # open the pay page and waitblast verify --claim <id>      # collect later (claims survive restarts for 30 days)blast verify --list            # unfinished claims on this machine

MCP: blast_verify_quote → pay → blast_collect. Payments are final. Need a wallet? abr.kloudle.dev/wallet.

Never sent: credential values, profile names, environment variable names, file paths, scan output. See abr.kloudle.dev/privacy.

License

Proprietary — see LICENSE.txt. Free to use for checks on machines and accounts you own or are authorized to assess. Third-party notices: THIRD_PARTY_NOTICES.txt. Scanner source is private; this repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.

來源:README.md,提交 606bf33

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.0最新Oct 2, 2026