Skip to main content
ClaudeWave
makash avatar
makash

agent-blast-radius

View on GitHub

Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private.

MCP ServersOfficial Registry0 stars0 forks● ShellNOASSERTIONUpdated today
ClaudeWave Trust Score
64/100
· OK
Passed
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Documented (README)
Flags
  • !Licence file present but not machine-readable
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: NPX · @kloudle/agent-blast-radius
Claude Code CLI
claude mcp add agent-blast-radius -- npx -y @kloudle/agent-blast-radius
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "agent-blast-radius": {
      "command": "npx",
      "args": ["-y", "@kloudle/agent-blast-radius"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

# Agent Blast Radius

**What could an agent running as you reach?** `blast` scans the places a coding agent
running as you can read — cloud profiles, dotfiles, project `.env` files, CI configs,
MCP servers — and tells you what is exposed, scores it, and draws a card you can share.
Offline, read-only, never prints a secret value. Optionally, `blast verify` checks which
of those credentials are actually **live**, paid per check with your own wallet.

```sh
npx -y @kloudle/agent-blast-radius@0.3.0          # scan + share card (free, offline)
npx -y @kloudle/agent-blast-radius@0.3.0 verify   # which keys work? (paid, optional)
```

More at **[abr.kloudle.dev](https://abr.kloudle.dev)**.

## Install it where your agent runs

| Where | How |
|---|---|
| Any terminal | `npx -y @kloudle/agent-blast-radius@0.3.0` · `brew install makash/tap/blast` · `curl -fsSL https://abr.kloudle.dev/install.sh \| sh` |
| Claude Code | `/plugin marketplace add makash/agent-blast-radius` then `/plugin install agent-blast-radius@kloudle` |
| Codex (CLI and app) | `codex plugin marketplace add makash/agent-blast-radius` then `codex plugin add agent-blast-radius@kloudle` |
| Claude Desktop | Download [`agent-blast-radius-0.3.0.mcpb`](https://github.com/makash/agent-blast-radius/releases/download/v0.3.0/agent-blast-radius-0.3.0.mcpb) and open it |
| Cursor | [Add to Cursor](https://abr.kloudle.dev/install/cursor) |
| VS Code | [Install in VS Code](https://abr.kloudle.dev/install/vscode) |
| Devin Desktop (Windsurf), Cline, Zed, any MCP client | `{"mcpServers":{"blast":{"command":"npx","args":["-y","@kloudle/agent-blast-radius@0.3.0","mcp"]}}}` |
| Agent Skills | `npx skills add makash/agent-blast-radius` |
| Rules files | [Cursor](rules/cursor/blast.mdc) · [Devin Desktop / Windsurf](rules/devin/blast.md) · [Cline](rules/cline/blast.md) |

Release binaries and `SHA256SUMS` are on [Releases](https://github.com/makash/agent-blast-radius/releases):
macOS and Linux, ARM64 and AMD64. They are not code-signed or notarized; verify the
checksum. The npm launcher and `install.sh` verify it for you. Node.js 22+ for `npx`.

## The scan

- Reports credential types, locations, SHA-256 fingerprints, local scope hints and
  configured MCP reachability. **Never values.**
- Makes no network calls, executes no MCP servers, uploads nothing, no telemetry.
- Writes a 1080 × 1350 PNG card and share text by default (`--anonymous` drops your
  username, `--no-card` skips files). Existing files are never overwritten.
- Scores are exposure estimates, not proof that a credential works or was compromised.

As an MCP server (`blast mcp`) it offers `blast_radius`, `explain_credential` and
`blast_card` (read-only, offline) plus the verify tools below.

## Which ones are live? `blast verify`

The scan can't tell a dead key from a live one. `blast verify`:

1. counts eligible findings (AWS profiles; `OPENAI_API_KEY` / `ANTHROPIC_API_KEY` in
   the environment) and creates a claim at abr.kloudle.dev with **class counts only**,
   e.g. `aws-sts-identity:2`;
2. prints the price — **$0.10 USDC per check on Algorand** — a code, and two ways to pay
   with your own wallet: your agent's x402 wallet tool (e.g. GoPlausible's
   `algorand-mcp`), or a browser link where you approve in Pera, Defly or Lute;
3. once paid, fetches an **Ed25519-signed** manifest, runs the checks on your machine
   (`aws sts get-caller-identity`, provider model-list probes) with a minimal
   environment, and reports each finding as live, rejected or error.

```sh
blast verify --open            # open the pay page and wait
blast verify --claim <id>      # collect later (claims survive restarts for 30 days)
blast verify --list            # unfinished claims on this machine
```

MCP: `blast_verify_quote` → pay → `blast_collect`. Payments are final.
Need a wallet? [abr.kloudle.dev/wallet](https://abr.kloudle.dev/wallet).

**Never sent:** credential values, profile names, environment variable names, file
paths, scan output. See [abr.kloudle.dev/privacy](https://abr.kloudle.dev/privacy).

## License

Proprietary — see [LICENSE.txt](LICENSE.txt). Free to use for checks on machines and
accounts you own or are authorized to assess. Third-party notices:
[THIRD_PARTY_NOTICES.txt](THIRD_PARTY_NOTICES.txt). Scanner source is private; this
repository distributes binaries, the npm launcher's metadata, plugins, skills and rules.

What people ask about agent-blast-radius

What is makash/agent-blast-radius?

+

makash/agent-blast-radius is mcp servers for the Claude AI ecosystem. Offline agent credential exposure checks. Proprietary binary downloads; scanner source is private. It has 0 GitHub stars and its last recorded update is dated 2026-10-02.

How do I install agent-blast-radius?

+

You can install agent-blast-radius by cloning the repository (https://github.com/makash/agent-blast-radius) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is makash/agent-blast-radius safe to use?

+

Our security agent has analyzed makash/agent-blast-radius and assigned a Trust Score of 64/100 (tier: OK). See the full breakdown of passed checks and flags on this page.

Who maintains makash/agent-blast-radius?

+

makash/agent-blast-radius is maintained by makash. The last recorded GitHub activity is dated 2026-10-02, with 0 open issues.

Are there alternatives to agent-blast-radius?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy agent-blast-radius to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: makash/agent-blast-radius
[![Featured on ClaudeWave](https://claudewave.com/api/badge/makash-agent-blast-radius)](https://claudewave.com/repo/makash-agent-blast-radius)
<a href="https://claudewave.com/repo/makash-agent-blast-radius"><img src="https://claudewave.com/api/badge/makash-agent-blast-radius" alt="Featured on ClaudeWave: makash/agent-blast-radius" width="320" height="64" /></a>

More MCP Servers

agent-blast-radius alternatives