The blast CLI scans the places a coding agent running as you can read: cloud profiles, dotfiles, project .env files, CI configs, MCP servers. It tells you what is exposed, scores it, and draws a card you can share. Free, offline, in about two seconds.
npx -y @kloudle/agent-blast-radius@0.3.0macOS and Linux, amd64 and arm64. No account, no network calls during the scan, no telemetry. Don't run it under sudo: the point is to see what you can reach.

Every default run writes a 1080×1350 PNG and a copyable caption next to it. It is built only from category counts. Paths, values, account IDs and fingerprints can't appear on it by construction.
--anonymous to drop it.In the terminal you get every observation: credential type, location, whether an agent can reach it, a scope hint and a SHA-256 fingerprint. Never the value.

Every option runs the same checksum-pinned binary. The scan is offline; nothing is sent anywhere.
| Where | How |
|---|---|
| Any terminal | npx -y @kloudle/agent-blast-radius@0.3.0brew install makash/tap/blastcurl -fsSL https://abr.kloudle.dev/install.sh | sh |
| Claude Code | /plugin marketplace add makash/agent-blast-radius/plugin install agent-blast-radius@kloudle |
| Codex (CLI and app) | codex plugin marketplace add makash/agent-blast-radiuscodex plugin add agent-blast-radius@kloudle |
| Claude Desktop | Download the extension (.mcpb), then open it (Settings → Extensions) |
| Cursor | Add to Cursor |
| VS Code | Install in VS Code |
| Devin Desktop (Windsurf), Cline, Zed and other MCP clients | Add this MCP server: |
| Agent Skills | npx skills add makash/agent-blast-radius |
| Rules files | Cursor · Devin Desktop / Windsurf · Cline |
| Just ask | Paste into any agent with a shell: Read https://abr.kloudle.dev/llms.txt and run the Agent Blast Radius scan for me. |
Release binaries and SHA256SUMS: GitHub releases. macOS and Linux, ARM64 and AMD64. Binaries are not code-signed; verify the checksum.
| Command | What it does |
|---|---|
blast | Table, PNG card and share caption |
blast --anonymous | Leave your username off the card |
blast --no-card | Table only, writes no files |
blast --card | Card and caption, no table |
blast --json | Full machine-readable report |
blast --explain <id> | Why one finding matters |
blast --projects-root ~/work | Scan specific project folders |
blast mcp | Run as a stdio MCP server |
blast verify | Check which keys are live (paid per check; prints how to pay) |
blast verify --open | Same, opening the browser pay page and waiting |
blast verify --claim <id> | Run a paid claim's checks on this machine |
blast verify --list | Unfinished claims on this machine |
The JSON and table output include paths and account hints. Keep those private; share the card.
The free scan can't tell a dead key from a live one. blast verify sends only how many checks of each type you want, you pay $0.10 USDC per check with your own Algorand wallet, and blast runs signed checks on your machine.
npx -y @kloudle/agent-blast-radius@0.3.0 verifyPay from your agent's x402 wallet or in a browser with Pera, Defly or Lute. Set up a wallet · How it works · Payments are final.