Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private.
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
- !Licence file present but not machine-readable
- !Install pipes a remote script into a shell (curl | sh)
claude mcp add agent-blast-radius -- npx -y @kloudle/agent-blast-radius{
"mcpServers": {
"agent-blast-radius": {
"command": "npx",
"args": ["-y", "@kloudle/agent-blast-radius"]
}
}
}MCP Servers overview
# Agent Blast Radius
**What could an agent running as you reach?** `blast` scans the places a coding agent
running as you can read — cloud profiles, dotfiles, project `.env` files, CI configs,
MCP servers — and tells you what is exposed, scores it, and draws a card you can share.
Offline, read-only, never prints a secret value. Optionally, `blast verify` checks which
of those credentials are actually **live**, paid per check with your own wallet.
```sh
npx -y @kloudle/agent-blast-radius@0.3.0 # scan + share card (free, offline)
npx -y @kloudle/agent-blast-radius@0.3.0 verify # which keys work? (paid, optional)
```
More at **[abr.kloudle.dev](https://abr.kloudle.dev)**.
## Install it where your agent runs
| Where | How |
|---|---|
| Any terminal | `npx -y @kloudle/agent-blast-radius@0.3.0` · `brew install makash/tap/blast` · `curl -fsSL https://abr.kloudle.dev/install.sh \| sh` |
| Claude Code | `/plugin marketplace add makash/agent-blast-radius` then `/plugin install agent-blast-radius@kloudle` |
| Codex (CLI and app) | `codex plugin marketplace add makash/agent-blast-radius` then `codex plugin add agent-blast-radius@kloudle` |
| Claude Desktop | Download [`agent-blast-radius-0.3.0.mcpb`](https://github.com/makash/agent-blast-radius/releases/download/v0.3.0/agent-blast-radius-0.3.0.mcpb) and open it |
| Cursor | [Add to Cursor](https://abr.kloudle.dev/install/cursor) |
| VS Code | [Install in VS Code](https://abr.kloudle.dev/install/vscode) |
| Devin Desktop (Windsurf), Cline, Zed, any MCP client | `{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/agent-blast-radius@0.3.0","mcp"]}}}` |
| Agent Skills | `npx skills add makash/agent-blast-radius` |
| Rules files | [Cursor](rules/cursor/blast.mdc) · [Devin Desktop / Windsurf](rules/devin/blast.md) · [Cline](rules/cline/blast.md) |
Release binaries and `SHA256SUMS` are on [Releases](https://github.com/makash/agent-blast-radius/releases):
macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the
checksum. The npm launcher and `install.sh` verify it for you. Node.js 22+ for `npx`.
## The scan
- Reports credential types, locations, SHA-256 fingerprints, local scope hints and
configured MCP reachability. **Never values.**
- Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
- Writes a 1080 × 1350 PNG card and share text by default (`--anonymous` drops your
username, `--no-card` skips files). Existing files are never overwritten.
- Scores are exposure estimates, not proof that a credential works or was compromised.
As an MCP server (`blast mcp`) it offers `blast_radius`, `explain_credential` and
`blast_card` (read-only, offline) plus the verify tools below.
## Which ones are live? `blast verify`
The scan can't tell a dead key from a live one. `blast verify`:
1. counts eligible findings (AWS profiles; `OPENAI_API_KEY` / `ANTHROPIC_API_KEY` in
the environment) and creates a claim at abr.kloudle.dev with **class counts only**,
e.g. `aws-sts-identity:2`;
2. prints the price — **$0.10 USDC per check on Algorand** — a code, and two ways to pay
with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's
`algorand-mcp`), or a browser link where you approve in Pera, Defly or Lute;
3. once paid, fetches an **Ed25519-signed** manifest, runs the checks on your machine
(`aws sts get-caller-identity`, provider model-list probes) with a minimal
environment, and reports each finding as live, rejected or error.
```sh
blast verify --open # open the pay page and wait
blast verify --claim <id> # collect later (claims survive restarts for 30 days)
blast verify --list # unfinished claims on this machine
```
MCP: `blast_verify_quote` → pay → `blast_collect`. Payments are final.
Need a wallet? [abr.kloudle.dev/wallet](https://abr.kloudle.dev/wallet).
**Never sent:** credential values, profile names, environment variable names, file
paths, scan output. See [abr.kloudle.dev/privacy](https://abr.kloudle.dev/privacy).
## License
Proprietary — see [LICENSE.txt](LICENSE.txt). Free to use for checks on machines and
accounts you own or are authorized to assess. Third-party notices:
[THIRD_PARTY_NOTICES.txt](THIRD_PARTY_NOTICES.txt). Scanner source is private; this
repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.
What people ask about agent-blast-radius
What is makash/agent-blast-radius?
+
makash/agent-blast-radius is mcp servers for the Claude AI ecosystem. Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private. It has 0 GitHub stars and its last recorded update is dated 2026-10-02.
How do I install agent-blast-radius?
+
You can install agent-blast-radius by cloning the repository (https://github.com/makash/agent-blast-radius) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is makash/agent-blast-radius safe to use?
+
Our security agent has analyzed makash/agent-blast-radius and assigned a Trust Score of 64/100 (tier: OK). See the full breakdown of passed checks and flags on this page.
Who maintains makash/agent-blast-radius?
+
makash/agent-blast-radius is maintained by makash. The last recorded GitHub activity is dated 2026-10-02, with 0 open issues.
Are there alternatives to agent-blast-radius?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy agent-blast-radius to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/makash-agent-blast-radius)<a href="https://claudewave.com/repo/makash-agent-blast-radius"><img src="https://claudewave.com/api/badge/makash-agent-blast-radius" alt="Featured on ClaudeWave: makash/agent-blast-radius" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.