Releases: makash/agent-blast-radius
Release list
Agent Blast Radius 0.3.0
Agent Blast Radius 0.3.0
Runs everywhere your agent does, and can now tell you which of your credentials are
live, paid per check with your own wallet.
npx -y @kloudle/agent-blast-radius@0.3.0 # scan (free, offline) + card
npx -y @kloudle/agent-blast-radius@0.3.0 verify # check which keys work (paid, optional)New
blast verify: live verification of eligible findings (AWS profiles; OpenAI and
Anthropic keys in the environment). blast creates a claim at abr.kloudle.dev that
carries only class counts (for exampleaws-sts-identity:2), you or your agent pay
$0.10 USDC per check on Algorand with your own wallet (x402), and blast fetches a
signed manifest and runs the checks on your machine. Credential values, profile
names, environment variable names, paths and scan output never leave it.- Pay from an agent's x402 wallet tool (e.g. GoPlausible's algorand-mcp) or in a
browser with Pera, Defly or Lute at abr.kloudle.dev/pay. --wait/--open,--claim IDto collect later (claim state survives restarts),
--list,--only,--max-checks,--json.- Manifests are Ed25519-signed; blast pins the key, runs only
awsandnode
verifiers, never a shell, and passes them a minimal environment. - Payments are final.
- Pay from an agent's x402 wallet tool (e.g. GoPlausible's algorand-mcp) or in a
- MCP tools
blast_verify_quote,blast_claim_status,blast_collect. The scan
tools stay read-only and offline. - Install anywhere: Claude Code and Codex plugin marketplace in this repository,
MCP registry entry, Cursor and VS Code install links, Agent Skills, Cursor / Devin
Desktop (Windsurf) / Cline rules, Homebrew tap, checksum-verifyinginstall.sh, and
a Claude Desktop extension (.mcpb).
Fixed
- The npm launcher now runs on stock Debian/Ubuntu, where
$HOMEand~/.cacheare
group-writable for the user's own group (775), and honoursXDG_CACHE_HOME. --paid-verify(which needed a pre-signed payment header the service never
accepted) is replaced byblast verify.
Unchanged
The scan is offline and read-only, reports redacted metadata only, and makes the same
1080 × 1350 card. Binaries are unsigned and not notarized; verify them against
SHA256SUMS. macOS and Linux, ARM64 and AMD64.
Agent Blast Radius 0.2.1
Agent Blast Radius 0.2.1
Patch release: generated captions now recommend the correct scoped command,
npx -y @kloudle/agent-blast-radius@0.2.1. Release verification now checks that
both saved and printed captions match the installed package name and version.
Existing v0.2.0 release files are unchanged.
One explicitly invoked command checks offline exposure, creates a social-ready
card, and prints a suggested caption:
npx -y @kloudle/agent-blast-radius@0.2.1Included
- Offline local credential exposure checks with redacted output.
- Built-in 1080 × 1350 PNG generation and suggested share text by default.
- A system-username card title;
--anonymousremoves the username. --no-cardto suppress the default card and share-text files.- Checksum-pinned npm launcher; installing alone does not download a binary or scan.
- macOS and Linux binaries for ARM64 and AMD64.
Package installation and the initial binary download need network access. A cached
launcher verifies and runs the binary locally, but npx itself may still contact
npm on later invocations. The scanner's checks are offline; no discovered
credentials or scan reports are uploaded. Scores are heuristic exposure estimates,
not proof of account access. Review generated cards and captions before sharing.
Account lookup ignores inherited USER and LOGNAME values and falls back to
anonymous output on failure or after 250 ms. Linux uses a bounded /etc/passwd
lookup. Unsupported font characters become spaced U+XXXX labels in PNG and SVG
cards, with a 60-character display limit including ... when truncated. Sharing
text retains the original sanitized username.
Output files are never overwritten. PNG and caption files are created separately
with owner-only permissions. If caption creation fails, the command reports
failure and a completed PNG may remain; existing text is preserved.
Not included
Online checks (future Pro), fleet management (future Pro Max), an enforced hosted
IP allowance, and billing are not implemented in this release. This is proprietary
software; scanner source is not included in this downloads-only repository.
Verify direct downloads
Choose the binary matching your operating system and CPU. Download SHA256SUMS
alongside it and verify the binary's SHA-256 before executing it. The npm launcher
performs checksum verification automatically using the hashes shipped in its
version-specific manifest.
These initial binaries are unsigned and are not notarized by Apple. Operating
system warnings or execution blocks are possible. Checksums establish integrity
against the published manifest, not an independent signing identity.
Agent Blast Radius 0.2.0
Agent Blast Radius 0.2.0
One explicitly invoked command checks offline exposure, creates a social-ready
card, and prints a suggested caption:
npx -y @kloudle/agent-blast-radius@0.2.0Included
- Offline local credential exposure checks with redacted output.
- Built-in 1080 × 1350 PNG generation and suggested share text by default.
- A system-username card title;
--anonymousremoves the username. --no-cardto suppress the default card and share-text files.- Checksum-pinned npm launcher; installing alone does not download a binary or scan.
- macOS and Linux binaries for ARM64 and AMD64.
Package installation and the initial binary download need network access. A cached
launcher verifies and runs the binary locally, but npx itself may still contact
npm on later invocations. The scanner's checks are offline; no discovered
credentials or scan reports are uploaded. Scores are heuristic exposure estimates,
not proof of account access. Review generated cards and captions before sharing.
Account lookup ignores inherited USER and LOGNAME values and falls back to
anonymous output on failure or after 250 ms. Linux uses a bounded /etc/passwd
lookup. Unsupported font characters become spaced U+XXXX labels in PNG and SVG
cards, with a 60-character display limit including ... when truncated. Sharing
text retains the original sanitized username.
Output files are never overwritten. PNG and caption files are created separately
with owner-only permissions. If caption creation fails, the command reports
failure and a completed PNG may remain; existing text is preserved.
Not included
Online checks (future Pro), fleet management (future Pro Max), an enforced hosted
IP allowance, and billing are not implemented in this release. This is proprietary
software; scanner source is not included in this downloads-only repository.
Verify direct downloads
Choose the binary matching your operating system and CPU. Download SHA256SUMS
alongside it and verify the binary's SHA-256 before executing it. The npm launcher
performs checksum verification automatically using the hashes shipped in its
version-specific manifest.
These initial binaries are unsigned and are not notarized by Apple. Operating
system warnings or execution blocks are possible. Checksums establish integrity
against the published manifest, not an independent signing identity.