Skip to main content
ClaudeWave
makash avatar
makash

agent-blast-radius

Ver en GitHub

Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private.

MCP ServersRegistry oficial0 estrellas0 forks● ShellNOASSERTIONActualizado today
ClaudeWave Trust Score
64/100
· OK
Passed
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Documented (README)
Flags
  • !Licence file present but not machine-readable
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: NPX · @kloudle/agent-blast-radius
Claude Code CLI
claude mcp add agent-blast-radius -- npx -y @kloudle/agent-blast-radius
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "agent-blast-radius": {
      "command": "npx",
      "args": ["-y", "@kloudle/agent-blast-radius"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Casos de uso

Resumen de MCP Servers

# Agent Blast Radius

**What could an agent running as you reach?** `blast` scans the places a coding agent
running as you can read — cloud profiles, dotfiles, project `.env` files, CI configs,
MCP servers — and tells you what is exposed, scores it, and draws a card you can share.
Offline, read-only, never prints a secret value. Optionally, `blast verify` checks which
of those credentials are actually **live**, paid per check with your own wallet.

```sh
npx -y @kloudle/agent-blast-radius@0.3.0          # scan + share card (free, offline)
npx -y @kloudle/agent-blast-radius@0.3.0 verify   # which keys work? (paid, optional)
```

More at **[abr.kloudle.dev](https://abr.kloudle.dev)**.

## Install it where your agent runs

| Where | How |
|---|---|
| Any terminal | `npx -y @kloudle/agent-blast-radius@0.3.0` · `brew install makash/tap/blast` · `curl -fsSL https://abr.kloudle.dev/install.sh \| sh` |
| Claude Code | `/plugin marketplace add makash/agent-blast-radius` then `/plugin install agent-blast-radius@kloudle` |
| Codex (CLI and app) | `codex plugin marketplace add makash/agent-blast-radius` then `codex plugin add agent-blast-radius@kloudle` |
| Claude Desktop | Download [`agent-blast-radius-0.3.0.mcpb`](https://github.com/makash/agent-blast-radius/releases/download/v0.3.0/agent-blast-radius-0.3.0.mcpb) and open it |
| Cursor | [Add to Cursor](https://abr.kloudle.dev/install/cursor) |
| VS Code | [Install in VS Code](https://abr.kloudle.dev/install/vscode) |
| Devin Desktop (Windsurf), Cline, Zed, any MCP client | `{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/agent-blast-radius@0.3.0","mcp"]}}}` |
| Agent Skills | `npx skills add makash/agent-blast-radius` |
| Rules files | [Cursor](rules/cursor/blast.mdc) · [Devin Desktop / Windsurf](rules/devin/blast.md) · [Cline](rules/cline/blast.md) |

Release binaries and `SHA256SUMS` are on [Releases](https://github.com/makash/agent-blast-radius/releases):
macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the
checksum. The npm launcher and `install.sh` verify it for you. Node.js 22+ for `npx`.

## The scan

- Reports credential types, locations, SHA-256 fingerprints, local scope hints and
  configured MCP reachability. **Never values.**
- Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
- Writes a 1080 × 1350 PNG card and share text by default (`--anonymous` drops your
  username, `--no-card` skips files). Existing files are never overwritten.
- Scores are exposure estimates, not proof that a credential works or was compromised.

As an MCP server (`blast mcp`) it offers `blast_radius`, `explain_credential` and
`blast_card` (read-only, offline) plus the verify tools below.

## Which ones are live? `blast verify`

The scan can't tell a dead key from a live one. `blast verify`:

1. counts eligible findings (AWS profiles; `OPENAI_API_KEY` / `ANTHROPIC_API_KEY` in
   the environment) and creates a claim at abr.kloudle.dev with **class counts only**,
   e.g. `aws-sts-identity:2`;
2. prints the price — **$0.10 USDC per check on Algorand** — a code, and two ways to pay
   with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's
   `algorand-mcp`), or a browser link where you approve in Pera, Defly or Lute;
3. once paid, fetches an **Ed25519-signed** manifest, runs the checks on your machine
   (`aws sts get-caller-identity`, provider model-list probes) with a minimal
   environment, and reports each finding as live, rejected or error.

```sh
blast verify --open            # open the pay page and wait
blast verify --claim <id>      # collect later (claims survive restarts for 30 days)
blast verify --list            # unfinished claims on this machine
```

MCP: `blast_verify_quote` → pay → `blast_collect`. Payments are final.
Need a wallet? [abr.kloudle.dev/wallet](https://abr.kloudle.dev/wallet).

**Never sent:** credential values, profile names, environment variable names, file
paths, scan output. See [abr.kloudle.dev/privacy](https://abr.kloudle.dev/privacy).

## License

Proprietary — see [LICENSE.txt](LICENSE.txt). Free to use for checks on machines and
accounts you own or are authorized to assess. Third-party notices:
[THIRD_PARTY_NOTICES.txt](THIRD_PARTY_NOTICES.txt). Scanner source is private; this
repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.

Lo que la gente pregunta sobre agent-blast-radius

¿Qué es makash/agent-blast-radius?

+

makash/agent-blast-radius es mcp servers para el ecosistema de Claude AI. Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-02.

¿Cómo se instala agent-blast-radius?

+

Puedes instalar agent-blast-radius clonando el repositorio (https://github.com/makash/agent-blast-radius) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar makash/agent-blast-radius?

+

Nuestro agente de seguridad ha analizado makash/agent-blast-radius y le ha asignado un Trust Score de 64/100 (tier: OK). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene makash/agent-blast-radius?

+

makash/agent-blast-radius es mantenido por makash. La última actividad registrada en GitHub es del 2026-10-02, con 0 issues abiertos.

¿Hay alternativas a agent-blast-radius?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega agent-blast-radius en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: makash/agent-blast-radius
[![Featured on ClaudeWave](https://claudewave.com/api/badge/makash-agent-blast-radius)](https://claudewave.com/repo/makash-agent-blast-radius)
<a href="https://claudewave.com/repo/makash-agent-blast-radius"><img src="https://claudewave.com/api/badge/makash-agent-blast-radius" alt="Featured on ClaudeWave: makash/agent-blast-radius" width="320" height="64" /></a>

Más MCP Servers

Alternativas a agent-blast-radius