Agent Blast Radiusby Kloudle

One command. Your blast radius on one card.

The blast CLI scans the places a coding agent running as you can read: cloud profiles, dotfiles, project .env files, CI configs, MCP servers. It tells you what is exposed, scores it, and draws a card you can share. Free, offline, in about two seconds.

$npx -y @kloudle/agent-blast-radius@0.3.0

macOS and Linux, amd64 and arm64. No account, no network calls during the scan, no telemetry. Don't run it under sudo: the point is to see what you can reach.

Example Agent Blast Radius card: score 97 of 100, SPICY, with counts for cloud, code, CI secrets, money and data, AI keys, and agent wiring
A card from a synthetic demo home. Yours is generated locally.

The card

Every default run writes a 1080×1350 PNG and a copyable caption next to it. It is built only from category counts. Paths, values, account IDs and fingerprints can't appear on it by construction.

0–33 LOCKED DOWN34–66 TOASTY67–100 SPICY
  • Six cells: Cloud, Code, CI secrets, Money & data, AI keys, Agent wiring.
  • Agent wiring is never counted. It lights up when MCP servers are configured, as a prompt to review them.
  • The title uses your system username. Add --anonymous to drop it.
  • Nothing is posted or copied for you. Review it, then share it if you want.

The table

In the terminal you get every observation: credential type, location, whether an agent can reach it, a scope hint and a SHA-256 fingerprint. Never the value.

Terminal output of blast showing a score of 97 and a table of stripe and supabase credentials found in .env files
Synthetic fixture, first eight observations.

Install it where your agent runs

Every option runs the same checksum-pinned binary. The scan is offline; nothing is sent anywhere.

WhereHow
Any terminalnpx -y @kloudle/agent-blast-radius@0.3.0
brew install makash/tap/blast
curl -fsSL https://abr.kloudle.dev/install.sh | sh
Claude Code/plugin marketplace add makash/agent-blast-radius
/plugin install agent-blast-radius@kloudle
Codex (CLI and app)codex plugin marketplace add makash/agent-blast-radius
codex plugin add agent-blast-radius@kloudle
Claude DesktopDownload the extension (.mcpb), then open it (Settings → Extensions)
CursorAdd to Cursor
VS CodeInstall in VS Code
Devin Desktop (Windsurf), Cline, Zed and other MCP clientsAdd this MCP server:
{
  "mcpServers": {
    "blast": {
      "command": "npx",
      "args": [
        "-y",
        "@kloudle/agent-blast-radius@0.3.0",
        "mcp"
      ]
    }
  }
}
Agent Skillsnpx skills add makash/agent-blast-radius
Rules filesCursor · Devin Desktop / Windsurf · Cline
Just askPaste into any agent with a shell: Read https://abr.kloudle.dev/llms.txt and run the Agent Blast Radius scan for me.

Release binaries and SHA256SUMS: GitHub releases. macOS and Linux, ARM64 and AMD64. Binaries are not code-signed; verify the checksum.

Useful flags

CommandWhat it does
blastTable, PNG card and share caption
blast --anonymousLeave your username off the card
blast --no-cardTable only, writes no files
blast --cardCard and caption, no table
blast --jsonFull machine-readable report
blast --explain <id>Why one finding matters
blast --projects-root ~/workScan specific project folders
blast mcpRun as a stdio MCP server
blast verifyCheck which keys are live (paid per check; prints how to pay)
blast verify --openSame, opening the browser pay page and waiting
blast verify --claim <id>Run a paid claim's checks on this machine
blast verify --listUnfinished claims on this machine

The JSON and table output include paths and account hints. Keep those private; share the card.

Next: check which ones are live

The free scan can't tell a dead key from a live one. blast verify sends only how many checks of each type you want, you pay $0.10 USDC per check with your own Algorand wallet, and blast runs signed checks on your machine.

$npx -y @kloudle/agent-blast-radius@0.3.0 verify

Pay from your agent's x402 wallet or in a browser with Pera, Defly or Lute. Set up a wallet · How it works · Payments are final.