Data Breach Blast Radius
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
Draw a task's blast radius twice. An agent skill from ayoubben18/ab-method.
$ npx skills add ayoubben18/ab-method --skill change-map -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ayoubben18/ab-method change-map --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/change-map .claude/skills/change-map && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .claude/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-mapType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ayoubben18/ab-method --skill change-map -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ayoubben18/ab-method change-map --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/change-map .agents/skills/change-map && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .agents/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ayoubben18/ab-method --skill change-map -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ayoubben18/ab-method change-map --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/change-map .cursor/skills/change-map && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .cursor/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ayoubben18/ab-method.git --path .agents/skills/change-map--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ayoubben18/ab-method --skill change-map -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ayoubben18/ab-method change-map --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/change-map .gemini/skills/change-map && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .gemini/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ayoubben18/ab-method change-mapInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ayoubben18/ab-method --skill change-map -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/change-map .github/skills/change-map && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .github/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ayoubben18/ab-method --skill change-map -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ayoubben18/ab-method change-map --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ayoubben18/ab-method.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/change-map .opencode/skills/change-map && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "change-map" agent skill from https://github.com/ayoubben18/ab-method/tree/main/.agents/skills/change-map into .opencode/skills/change-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "change-map", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
change-mapDraw a task's blast radius twice. An agent skill from ayoubben18/ab-method.
Change Map is an agent skill from ayoubben18/ab-method. Draw a task's blast radius twice. BEFORE implementing, a PLANNED map of the modules the missions expect to add, change or touch; AFTER the reviewers pass, an ACTUAL map derived from the real diff, plus the DRIFT between them. Writes docs/tasks/<task/change-map.md. Use from create-task / extend-task (planned pass), and after review-implementation + sync-architecture in create-task / resume-task / start-task / start-roadmap (actual pass), or standalone on a task.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `DIAGRAM-FORMAT.md`).
The repository describes itself as: A workflow system for Claude Code and Codex. It grills a problem into a domain-grounded plan, then either drives it through test-driven missions you review one at a time, or… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 85946e3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Change Map loads about 2.9k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 1,633 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ayoubben18/ab-method at commit 85946e3, republished under its MIT licence (© ayoubben18). 1,633 words, ~2,898 tokens.
.claude/skills/change-map/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.The artifact that answers "where in the codebase does this task live?" — asked twice, on purpose:
Where the other post-implementation skills judge the change — ../review-implementation/SKILL.md asks "is this good code?", ../sync-architecture/SKILL.md asks "do the docs know about it?" — this one only describes its shape. It never reviews code, never edits code, never edits the architecture docs.
Reduction is the point. A task that touched 40 files gets 6 rows; the cap is 10. A map that reads as an inventory of the diff has failed — the tracker's mission summaries already list the files. The map exists to be understood in seconds, months later, by someone who will not read the diff.
ALWAYS check .ab-method/structure/index.yaml FIRST for where tasks and the architecture/domain docs
live — paths are user-configurable. The rendering rules, the line types, and a full worked file live in
DIAGRAM-FORMAT.md; read it before drawing either pass.
Look for it under the project root (the current working directory) first — a project's own copy is how it
customises its paths, so it always wins. Only if the project has none (AB Method installed as a plugin rather than
with npx ab-method), read the bundled default: ../../../.ab-method/structure/index.yaml relative to this
SKILL.md. Either way, every path the index names is relative to the project root, never to the folder the
bundled file lives in.
Not "a directory". The map partitions the codebase the way this project partitions it, in this order:
CONTEXT.md / CONTEXT-MAP.md — the bounded contexts, named in the project's own ubiquitous
language. Best source by far: the map then speaks the domain, and a row nobody predicted reads as a
context boundary being crossed, not as "another folder changed".docs/architecture/* — documented entry points, layers, and pattern groupings.A module is a module in the ../codebase-design/SKILL.md sense — an interface with an implementation hidden behind it — and rows are named the way the docs already name it. Never invent a taxonomy the project doesn't use; a map in private vocabulary is unreadable to everyone but the session that drew it.
When: /create-task § 7.6 (after critique-plan, before the user validates the plan) and
/extend-task (appended for the new missions). It is drawn from the plan, never from code you wrote.
Inputs: the drafted missions, the grill's constraints and existing-code anchors, the architecture +
domain docs, and enough of a read of the named modules to tell [NEW] from [extended].
M2 · M4).+ lines list only interfaces the plan actually commits to — an endpoint the mission names, a
function the grill agreed on, a type the tracker records. If the plan names none, omit the line. A
predicted symbol nobody promised is the single thing that makes the later drift meaningless: it turns a
prediction into a guess, and drift against a guess measures nothing.└ will use, ▲ will be called by) only where a mission genuinely crosses them.→ line — one sentence on what this module will do that it doesn't today — is mandatory. A row
with an unwritten → is not publishable.If drawing the map forces you to invent a module, the plan is wrong — not the map. This pass is a
second read on the missions: a module you can't attribute to a mission, or a mission whose row you can't
place anywhere, is a planning gap critique-plan didn't catch. Say so out loud and fix the missions
before the user validates them. That is most of this pass's value; the picture is the by-product.
The planned map is shown to the user in /create-task § 8 alongside the mission list — they are
validating the blast radius, not just the sentences.
When: after review-implementation and sync-architecture have run, before the task's status is set
to Completed. Not earlier: the reviewers apply safe fixes and commit append-only doc additions, so a map
drawn before them describes a diff that no longer exists.
Derive it from the task's commit range, never the working tree:
git diff --name-status -M <base>..<head> # what changed, and how
git diff --numstat -M <base>..<head> # how much, for the verdicts<base>..<head> is the task's own range — the parent of its first mission commit through the last commit
the task made (including the review and doc-sync commits). If the working tree is dirty, say so and commit
first; a map of uncommitted work is not reproducible.
Verdicts here are derived, not judged (thresholds in DIAGRAM-FORMAT.md). The
+ / − lines are exported symbols that exist at head but not base, or the reverse — re-exports and
export default are skipped, because a barrel forwarding a symbol is not new logic. A − line is often
the most informative thing on the page: it is where the task removed a concept.
Generated and vendored files (lockfiles, migration snapshots, generated route trees, i18n catalogs, build
output) are excluded from ranking, so a 9,000-line generated file can't push the real change off the
map. They still appear in the also touched: tail.
Write each → line after reading the module — never paraphrased from the symbol names. Names say what
moved; only the sentence says what it now does.
Three findings, in a table (format in DIAGRAM-FORMAT.md):
[touched] → [rewritten],
[extended] → [NEW] siblings). The plan under-read the work.A task that landed where its plan said gets exactly one line — No drift — the change landed where the plan said it would. — and that is the good, common outcome for a well-grilled task. Never manufacture
drift to look thorough.
What drift is actually for. It routes; it never fixes:
| Drift pattern | What it means | Route to |
|---|---|---|
| The same unplanned module keeps appearing across tasks | Changes keep leaking there — a locality problem | /improve-codebase-architecture (codebase-design: leverage, locality) |
| An unplanned row crosses a bounded context | The boundary in CONTEXT.md may be drawn in the wrong place | /domain-model |
| A predicted-untouched row whose mission claimed it | The mission may not have done what its summary says | Re-read that mission before setting the task Completed |
| Wide drift on almost every task | Missions are being drafted without reading the code | /create-task § 2 — the project-analysis step is being skipped |
change-map.mdWritten next to progress-tracker.md, at docs/tasks/<task>/change-map.md.
## Planned only.## Actual and ## Drift.The actual pass never rewrites ## Planned. The planned map is a record of what you believed before
you knew, and it stays wrong on the page — editing it to match reality destroys the only thing the file is
for.
Interactive (/create-task, /resume-task, /extend-task, standalone): show the map inline. On the
actual pass, walk the drift findings with the user before closing the task.
Autonomous (/start-task, /start-roadmap): write the file, commit it as
docs(<task>): change map (repo convention), and put the drift lines in the run's final report. Never
prompt — an afk user must not discover a wider-than-planned blast radius by accident.
A task created before this skill existed, or one you're mapping standalone, has no ## Planned section.
Draw ## Actual and record Drift: no planned map — nothing to compare.
Never back-fill a planned map from the diff. A prediction reverse-engineered from the answer is a lie, and every drift computation that reads the file afterwards inherits it.
It does not review the change (that's review-implementation), does not update the architecture or domain
docs (that's sync-architecture / /update-architecture), and does not edit code. It only describes
shape. Keep it that way: judgment living in two places drifts, and a map that argues stops being a map.
CONTEXT.md and the architecture docs, never a taxonomy you made up./improve-codebase-architecture, /domain-model, or a re-read of a mission..ab-method/structure/index.yaml for paths; read DIAGRAM-FORMAT.md before drawing.critique-plan (missions may still change) and before the user validates.review-implementation and sync-architecture — their commits are part of the diff it maps.→ is written by you, after reading the module. A map shipped with an unfilled → advertises that nobody read the change.## Actual block plus its also touched: line is exactly what goes at the top of this task's PR body.© ayoubben18, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/change-map of ayoubben18/ab-method.
Open the folder on GitHubat commit 85946e3
Change Map next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Change Map this skillayoubben18/ab-method | 192 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Data Breach Blast Radiusgithub/awesome-copilot | 40k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Blast Radius Checkcursor/plugins | 10k | 9 repos | ~964 | Automated safety check: Pass | None | |
| Blast Radiuspedrohcgs/claude-code-my-workflow | 1.7k | — | ~1.5k | Automated safety check: Notes | MIT | |
| Token Mapnexu-io/open-design | 100k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Maps Geographyasgeirtj/system_prompts_leaks | 69k | — | ~717 | Automated safety check: Pass | CC0-1.0 |
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
cursor/plugins
Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.
pedrohcgs/claude-code-my-workflow
Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.
nexu-io/open-design
Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.
asgeirtj/system_prompts_leaks
Accurate maps from real geo data — use for any map, or whenever geography would make a good graphic for a deliverable
onyx-dot-app/onyx
Use the Onyx feature map (.agents/feature-map/) to learn what a product surface does, the code behind it, and what a change can break.
ayoubben18/ab-method
Shared vocabulary and principles for designing deep modules — small interfaces, clean seams, testable through the interface.
ayoubben18/ab-method
Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise.
ayoubben18/ab-method
Compact the current conversation (or a side-topic that surfaced mid-grill) into a handoff document another agent can pick up.
ayoubben18/ab-method
Scan a codebase for deepening opportunities, present them as a visual HTML report, then grill through whichever one you pick.
ayoubben18/ab-method
Cross-plan coherence critic for a whole roadmap. An agent skill from ayoubben18/ab-method.
ayoubben18/ab-method
Post-implementation review. An agent skill from ayoubben18/ab-method.
Draw a task's blast radius twice. An agent skill from ayoubben18/ab-method. Change Map is an agent skill from ayoubben18/ab-method. Draw a task's blast radius twice.
Run `npx skills add ayoubben18/ab-method --skill change-map -a claude-code`. Or copy the skill folder (.agents/skills/change-map in ayoubben18/ab-method) into .claude/skills/change-map in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ayoubben18/ab-method --skill change-map -a codex`. Or copy the skill folder (.agents/skills/change-map in ayoubben18/ab-method) into .agents/skills/change-map in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ayoubben18/ab-method --skill change-map -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/change-map, .gemini/skills/change-map, .github/skills/change-map and .opencode/skills/change-map in your project.
Going by SKILL.md and its folder, Change Map needs the command-line tools its instructions call (git and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Change Map is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Change Map: Data Breach Blast Radius (github/awesome-copilot, 40k stars), Blast Radius Check (cursor/plugins, 10k stars), Blast Radius (pedrohcgs/claude-code-my-workflow, 1.7k stars) and Token Map (nexu-io/open-design, 100k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ayoubben18 (a GitHub user) maintains it in ayoubben18/ab-method, which has 192 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 1, 2026.
Source: ayoubben18/ab-method on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.