Agent Blast Radiusby Kloudle

Answers / What Is Agent Blast Radius?

Definition

What is agent blast radius?

Agent blast radius is everything an AI coding agent could read or use because it runs with your operating system user's own permissions: API keys, cloud credentials, SSH keys, kubeconfig files, and MCP server configs. If your account can read a file, the agent can too, whether you intended that or not. You measure your own exposure locally with the blast CLI, which scores it from 0 to 100 without reading out any credential values.

Updated · Kloudle

Why does 'blast radius' mean something different for an AI coding agent?

In security, blast radius traditionally describes what a single compromised credential or service can reach. An AI coding agent changes the math because it doesn't hold a narrow service credential — it runs as you, inside your terminal or editor, with your shell's environment and your file permissions. Anything your user account can open, the agent's tool calls can open too: your AWS profile, your SSH keys, your npm token, a teammate's API key sitting in a stray .env file.

That's the sense this site uses: agent blast radius is the inventory of local credentials and configuration an agent could reach by virtue of running as you, not a hypothetical about what a sophisticated attacker might eventually pivot to.

How do other security vendors define 'blast radius'?

The phrase gets used for different things. Keeper Security's AI Agent Blast Radius Calculator is a ten-question organizational questionnaire that scores a company's overall AI-agent risk posture across attack surface, credential risk, governance, and detection gaps — a self-assessment, not a scan of any machine.

Obsidian Security's AI Blast Radius page defines it as the scope of an agent's authority inside connected SaaS apps: what it can do through delegated entitlements, OAuth grants, and inherited credentials, correlated with who invoked it. Their framing: configuration is not reality.

The nhimg.org glossary entry for agentic blast radius is closer to our usage: the scope of damage possible if an agent's identity or credentials are compromised, amplified by its autonomy and ability to chain actions quickly. We apply that idea specifically to what sits on a developer's own machine, reachable by a coding agent today — not a hypothetical breach.

How do you measure your own agent blast radius locally?

Agent Blast Radius (blast, by Kloudle) runs a local, offline, read-only scan that takes about two seconds. It never prints a credential's value — it reports the credential type, where it lives, a SHA-256 fingerprint, local scope hints, and whether any configured MCP server could reach it.

It covers categories like AWS and GCP credential files, Azure token caches, Kubernetes kubeconfig contexts, Docker inline auth, developer CLIs such as GitHub, npm, Cargo, SSH keys, Terraform, and Vercel, project files under common code directories, MCP configs for Claude Desktop, Claude Code, Cursor, Windsurf, and Gemini, and process environment variables. Run it with npx -y @kloudle/agent-blast-radius@0.3.0, or see the install guide for your platform and agent.

What does the blast radius score actually mean?

The scan produces a single score from 0 to 100: 0–33 is LOCKED DOWN, 34–66 is TOASTY, and 67–100 is SPICY, alongside a table of what was found and JSON output for scripting. The score is an exposure estimate — what a coding agent running as you could reach — not proof that any credential has been used or stolen.

It also isn't a sandbox or a firewall: blast shows you what's exposed, it doesn't block an agent from reading anything. For live-credential confirmation, an optional paid check can test whether an AWS profile or an OpenAI or Anthropic key actually authenticates, for $0.10 per check; everything else is left as an estimate.

Check your own machine

See what an agent running as you can reach. Offline, read-only, never prints values:

$npx -y @kloudle/agent-blast-radius@0.3.0

Inside your agent: install guides for Claude Code, Codex, Cursor, Claude Desktop and more. Which keys are live? npx -y @kloudle/agent-blast-radius@0.3.0 verify (paid per check).

Frequently asked

Does a high blast radius score mean I've been hacked?

No. The score is an exposure estimate — what a coding agent running as your user could read — not evidence that a credential was used or stolen.

Does scanning for blast radius send anything to a server?

No. The scan is local, offline, and read-only, and it never prints credential values. Only the optional paid verification feature sends anything, and only class counts, never values.

Is agent blast radius the same as attack surface?

They overlap but aren't identical. Attack surface is every possible entry point into a system; blast radius is what's reachable once an agent, or an attacker riding on it, is already running with your permissions.

Does a low score mean I'm safe?

It means fewer local credentials were found exposed to a coding agent. It doesn't cover browser profiles, OS keychains, or encrypted secret stores, so treat it as one input, not a guarantee.

Sources

  1. AI Agent Blast Radius Calculator — Keeper Security
  2. AI Blast Radius — Obsidian Security
  3. Agentic Blast Radius — nhimg.org

Related