Agent Blast Radiusby Kloudle

What can your coding agent reach?

Straight answers about AI coding agents and credentials: what they can read, how secrets leak, and what to do about it.

Answers

Definition

What is agent blast radius?

Agent blast radius is everything an AI coding agent could read or use because it runs with your operating system user's own permissions: API keys, cloud credentials, SSH keys, kube…

Answer

Can Claude Code read my .env file?

Yes. Claude Code runs as your own user account, and file reads require no approval by default, so it can open .env the same way any program you run can. Deny rules, ignore-style se…

Answer

What can an AI coding agent access on my machine?

An AI coding agent that runs as your own user account can reach almost everything you can: cloud credential files, SSH keys, package-registry tokens, kubeconfig, shell history, env…

Answer

Can my MCP config leak hardcoded secrets?

Often, yes. MCP server configs for Claude Desktop, Cursor, and similar tools commonly store API keys and tokens directly in plaintext JSON or .env files instead of referencing a se…

Guide

How do you sandbox Claude Code, and what does sandboxing not cover?

Claude Code's built-in sandbox, turned on with /sandbox, restricts what Bash, PowerShell, and Monitor commands can write and which network hosts they can reach. By default it does …

Answer

Does Cursor expose my API keys or other secrets?

Cursor doesn't deliberately exfiltrate secrets, but two gaps let them leak: .cursorignore only hides files from the Agent's context and @ mentions, not from its terminal or MCP too…

Answer

Can prompt injection make a coding agent steal my AWS keys?

Yes. Documented research and real incidents show the same chain: a coding agent reads untrusted content (an issue, a ticket, a file), treats text inside it as instructions, and tho…

Answer

How do I check if an API key or AWS key is still live without sending it to a third party?

You don't need a third-party checker to find out if a key still works. For AWS, run aws sts get-caller-identity --profile <name> locally — it calls AWS directly and r…

Answer

Can an AI agent read secrets from my shell history?

Yes. Bash and zsh write every command you run to ~/.bash_history or ~/.zsh_history, including secrets typed inline — export FOO=sk-..., curl -H "Authorization: Bearer ..."…

Answer

Can an AI coding agent use my kubeconfig / access my Kubernetes cluster?

Yes, if the agent can run shell commands. ~/.kube/config lists contexts — cluster endpoints bundled with user credentials, which may be an embedded bearer token, a client certifica…

Compare