Agent skill

Blast Radius

by chmonitor in chmonitor/chmonitor

Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.

GPL-3.0Auto-check passed

Install Blast Radius

skills CLI
$ npx skills add chmonitor/chmonitor --skill blast-radius -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install chmonitor/chmonitor blast-radius --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .claude/skills/blast-radius && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blast-radius
GitHub stars
298
Used in
2 other repos
Token cost
~1k tokens
SKILL.md length
671 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
GPL-3.0

At a glance

Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.

  • Works in 5 steps: You said so. Worthless on its own. → You pointed at the line. A real… → You showed the bad case can't happen.… → …
  • Blast radius of X
  • SKILL.md covers Don't trust your own writeup, Steps and What to hand back
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Blast Radius is an agent skill from chmonitor/chmonitor. Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Use for 'blast radius of X', 'what could this break', reviewing a small diff you don't trust, or a brief that asserts something about existing code ('make X public', 'X already handles Y') before you design against that assertion.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.

When your agent uses it

  • Blast radius of X
  • What could this break
  • Reviewing a small diff you dont trust
  • A brief that asserts something about existing code (make X public

Example prompts

  • “blast radius of X”
  • “what could this break”
  • “t trust, or a brief that asserts something about existing code (”
  • “/blast-radius”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. You said so. Worthless on its own.
  2. You pointed at the line. A real file:line, or the library's own source.
  3. You showed the bad case can't happen. You walked the failure step by step and it doesn't reach.
  4. You ran it. A script or test that calls the real code and fails loud if you're wrong.
  5. You reproduced it in the running app.

What it can do on your machine

Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blast Radius loads about 1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 671 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 671 words, ~1,041 tokens.

Download SKILL.mdSave it as .claude/skills/blast-radius/SKILL.md (or your agent's skills folder).
name
blast-radius
description
Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Use for 'blast radius of X', 'what could this break', reviewing a small diff you don't trust, or a brief that asserts something about existing code ('make X public', 'X already handles Y') before you design against that assertion.

Blast radius

Find what a change breaks somewhere else, before it ships. Use for "blast radius of X", "what could this break", or reviewing a small diff you don't trust yet. Run it before design, not only before shipping, when a brief asserts something about existing code ("make endpoint X public"): the assertion is a hypothesis, and the consumer census is what decides the design.

Companion to how and why. how tells you what the code does. why tells you why it's shaped that way. Blast radius tells you what it breaks somewhere else.

Listing the callers is not the job. The agent can grep those in a second. The job is the breakage grep won't show you.

Don't trust your own writeup

A blast-radius writeup that sounds right is worthless. It reads as convincing whether or not it's true. So don't hand back the writeup. Find the one or two facts the whole thing depends on and prove them by running code.

How sure are you

For each fact the change's safety depends on, get it as far down this list as is cheap, and say where it stopped.

  1. You said so. Worthless on its own.
  2. You pointed at the line. A real file:line, or the library's own source.
  3. You showed the bad case can't happen. You walked the failure step by step and it doesn't reach.
  4. You ran it. A script or test that calls the real code and fails loud if you're wrong.
  5. You reproduced it in the running app.

Step 4 is usually one small script that imports the same library the app ships and calls the exact function you're worried about.

Steps

  1. Read the change. The diff, the symbols it adds, changes, and deletes, and what it now does differently, including the part the diff doesn't spell out. Use why step 2 to pull the PR and commits.
  2. Find the one fact it's safe because of. Most changes that look risky are safe because of a single fact, like "this call only drops already-dead cache entries and does nothing else". Find that fact. If it holds, most risky cases are cleared at once. Spend your time here, not on a long list of maybes.
  3. Look where grep stops. Read the source of the library you call, and check its pinned version and any local patch. Work out when things run: microtasks, unmount and teardown, Solid versus React. Follow what a symbol search misses: the JSON an API returns, a DB column, a wire format, another language reading the same bytes, a feature flag, code three hops downstream.
  4. Be honest about each risk. Give it a real chance of happening and a real cost if it does. Keep the risks you confirmed. List the ones you checked and cleared separately. Same rules as why. Cite a real file:line, a search that finds nothing is still an answer, and never make up a caller or an API.
  5. Prove the one fact. Write a script or test that runs the real code, run it, and paste what happened.
  6. For a big or wide change, run it as an arena. Ask several models the same question and merge the answers. Different models catch different real bugs.
Show full SKILL.md (123 more words)Show less

What to hand back

  • What it does. What changed, including the part that isn't obvious.
  • The one fact it's safe because of. State it, say which step you got it to, and show the proof. If you couldn't prove it, write unproven.
  • Risks. Each names how it breaks, the file:line, how likely and how bad, and how to check. Paste the proof for the ones that matter.
  • Cleared. What you checked and why it's fine.
  • Before you merge. The cheapest test or repro that catches the real bug, including the script you wrote.

Write it through unslop, cite real code, and strip anything private before it goes anywhere public.

Reply: the writeup above, with the one safety fact either proven or marked unproven.

© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pstack/upstream/skills/blast-radius of chmonitor/chmonitor.

Open the folder on GitHubat commit fc39ef0

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in chmonitor/chmonitor, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Blast Radius next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blast Radius compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blast Radius this skillchmonitor/chmonitor2982 repos~1kAutomated safety check: PassGPL-3.0
Data Breach Blast Radiusgithub/awesome-copilot40k1 repos~3.6kAutomated safety check: NotesMIT
Blast Radius Checkcursor/plugins10k9 repos~964Automated safety check: PassNone
Blast Radiuspedrohcgs/claude-code-my-workflow1.6k—~1.5kAutomated safety check: NotesMIT
Blast Radius Drillmohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMIT
V5 Breaking Changesremotion-dev/remotion62k—~879Automated safety check: PassCustom licence

Similar skills

  • Data Breach Blast Radius

    github/awesome-copilot

    Official

    Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

    40k GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check: notes
  • Blast Radius Check

    cursor/plugins

    Official

    Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.

    10k GitHub starsUsed in 9 repos~964 tokens
    DevelopmentAuto-check passed
  • Blast Radius

    pedrohcgs/claude-code-my-workflow

    Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.

    1.6k GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check: notes
  • Blast Radius Drill

    mohitagw15856/pm-claude-skills

    Run the worst-case drill before an agent goes autonomous — the 'if this agent were fully hijacked right now, what's the damage' walk-through, the containment controls (caps, kill-switch…

    1.4k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • V5 Breaking Changes

    remotion-dev/remotion

    Official

    Implement or review a Remotion 5 breaking change while the v4 and v5 release lines still share code.

    62k GitHub stars~879 tokensUpdated today
    Media & CreativeAuto-check passed
  • Email Blast

    antiwork/gumroad

    Send one-off email blasts to Gumroad creators directly via production console, no PR or deploy needed.

    9.8k GitHub stars~1.4k tokensUpdated today
    DatabasesAuto-check passed

More from chmonitor/chmonitor

All 53 skills in this repo
  • Hyperframes Creative

    chmonitor/chmonitor

    Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.

    298 GitHub starsUsed in 5 repos~1.3k tokens
    Auto-check passed
  • Hyperframes Media

    chmonitor/chmonitor

    Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…

    298 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: notes
  • Remotion To Hyperframes

    chmonitor/chmonitor

    Port an existing Remotion (React) composition to HyperFrames HTML.

    298 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Music To Video

    chmonitor/chmonitor

    A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.

    298 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes
  • Hyperframes Animation

    chmonitor/chmonitor

    All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…

    298 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Faceless Explainer

    chmonitor/chmonitor

    turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…

    298 GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check: notes

Questions about Blast Radius

What does Blast Radius do?

Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Blast Radius is an agent skill from chmonitor/chmonitor. Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.

When should I use Blast Radius?

Blast Radius fits situations like: blast radius of X; what could this break; reviewing a small diff you dont trust; A brief that asserts something about existing code (make X public.

How do I install Blast Radius in Claude Code?

Run `npx skills add chmonitor/chmonitor --skill blast-radius -a claude-code`. Or copy the skill folder (.claude/skills/pstack/upstream/skills/blast-radius in chmonitor/chmonitor) into .claude/skills/blast-radius in your project. Claude Code loads it when a task matches its description.

How do I install Blast Radius in Codex?

Run `npx skills add chmonitor/chmonitor --skill blast-radius -a codex`. Or copy the skill folder (.claude/skills/pstack/upstream/skills/blast-radius in chmonitor/chmonitor) into .agents/skills/blast-radius in your project. Codex loads it when a task matches its description.

Can I use Blast Radius in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blast-radius, .gemini/skills/blast-radius, .github/skills/blast-radius and .opencode/skills/blast-radius in your project.

What does Blast Radius need to run?

SKILL.md names no scripts, command-line tools or credentials: Blast Radius is instructions for the agent only.

Does Blast Radius access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Blast Radius safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Blast Radius use?

Blast Radius is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blast Radius use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blast Radius?

Skills that share tags, products or a category with Blast Radius: Data Breach Blast Radius (github/awesome-copilot, 40k stars), Blast Radius Check (cursor/plugins, 10k stars), Blast Radius (pedrohcgs/claude-code-my-workflow, 1.6k stars) and Blast Radius Drill (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blast Radius?

chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 298 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.

Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.