Data Breach Blast Radius
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.
$ npx skills add chmonitor/chmonitor --skill blast-radius -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install chmonitor/chmonitor blast-radius --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .claude/skills/blast-radius && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .claude/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radiusType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add chmonitor/chmonitor --skill blast-radius -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install chmonitor/chmonitor blast-radius --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .agents/skills/blast-radius && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .agents/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill blast-radius -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install chmonitor/chmonitor blast-radius --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .cursor/skills/blast-radius && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .cursor/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/chmonitor/chmonitor.git --path .claude/skills/pstack/upstream/skills/blast-radius--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add chmonitor/chmonitor --skill blast-radius -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install chmonitor/chmonitor blast-radius --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .gemini/skills/blast-radius && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .gemini/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install chmonitor/chmonitor blast-radiusInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add chmonitor/chmonitor --skill blast-radius -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .github/skills/blast-radius && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .github/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill blast-radius -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install chmonitor/chmonitor blast-radius --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/pstack/upstream/skills/blast-radius .opencode/skills/blast-radius && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.claude/skills/pstack/upstream/skills/blast-radius into .opencode/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
blast-radiusFind what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.
Blast Radius is an agent skill from chmonitor/chmonitor. Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Use for 'blast radius of X', 'what could this break', reviewing a small diff you don't trust, or a brief that asserts something about existing code ('make X public', 'X already handles Y') before you design against that assertion.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Blast Radius loads about 1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 671 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 671 words, ~1,041 tokens.
.claude/skills/blast-radius/SKILL.md (or your agent's skills folder).Find what a change breaks somewhere else, before it ships. Use for "blast radius of X", "what could this break", or reviewing a small diff you don't trust yet. Run it before design, not only before shipping, when a brief asserts something about existing code ("make endpoint X public"): the assertion is a hypothesis, and the consumer census is what decides the design.
Companion to how and why. how tells you what the code does. why tells you why it's shaped that way. Blast radius tells you what it breaks somewhere else.
Listing the callers is not the job. The agent can grep those in a second. The job is the breakage grep won't show you.
A blast-radius writeup that sounds right is worthless. It reads as convincing whether or not it's true. So don't hand back the writeup. Find the one or two facts the whole thing depends on and prove them by running code.
For each fact the change's safety depends on, get it as far down this list as is cheap, and say where it stopped.
file:line, or the library's own source.Step 4 is usually one small script that imports the same library the app ships and calls the exact function you're worried about.
why step 2 to pull the PR and commits.why. Cite a real file:line, a search that finds nothing is still an answer, and never make up a caller or an API.arena. Ask several models the same question and merge the answers. Different models catch different real bugs.file:line, how likely and how bad, and how to check. Paste the proof for the ones that matter.Write it through unslop, cite real code, and strip anything private before it goes anywhere public.
Reply: the writeup above, with the one safety fact either proven or marked unproven.
© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/pstack/upstream/skills/blast-radius of chmonitor/chmonitor.
Open the folder on GitHubat commit fc39ef0
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in chmonitor/chmonitor, which our catalogue first saw on October 7, 2026.
Blast Radius next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Blast Radius this skillchmonitor/chmonitor | 298 | 2 repos | ~1k | Automated safety check: Pass | GPL-3.0 | |
| Data Breach Blast Radiusgithub/awesome-copilot | 40k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Blast Radius Checkcursor/plugins | 10k | 9 repos | ~964 | Automated safety check: Pass | None | |
| Blast Radiuspedrohcgs/claude-code-my-workflow | 1.6k | — | ~1.5k | Automated safety check: Notes | MIT | |
| Blast Radius Drillmohitagw15856/pm-claude-skills | 1.4k | — | ~1.7k | Automated safety check: Pass | MIT | |
| V5 Breaking Changesremotion-dev/remotion | 62k | — | ~879 | Automated safety check: Pass | Custom licence |
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
cursor/plugins
Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.
pedrohcgs/claude-code-my-workflow
Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.
mohitagw15856/pm-claude-skills
Run the worst-case drill before an agent goes autonomous — the 'if this agent were fully hijacked right now, what's the damage' walk-through, the containment controls (caps, kill-switch…
remotion-dev/remotion
Implement or review a Remotion 5 breaking change while the v4 and v5 release lines still share code.
antiwork/gumroad
Send one-off email blasts to Gumroad creators directly via production console, no PR or deploy needed.
chmonitor/chmonitor
Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.
chmonitor/chmonitor
Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…
chmonitor/chmonitor
Port an existing Remotion (React) composition to HyperFrames HTML.
chmonitor/chmonitor
A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.
chmonitor/chmonitor
All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…
chmonitor/chmonitor
turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…
Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Blast Radius is an agent skill from chmonitor/chmonitor. Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up.
Blast Radius fits situations like: blast radius of X; what could this break; reviewing a small diff you dont trust; A brief that asserts something about existing code (make X public.
Run `npx skills add chmonitor/chmonitor --skill blast-radius -a claude-code`. Or copy the skill folder (.claude/skills/pstack/upstream/skills/blast-radius in chmonitor/chmonitor) into .claude/skills/blast-radius in your project. Claude Code loads it when a task matches its description.
Run `npx skills add chmonitor/chmonitor --skill blast-radius -a codex`. Or copy the skill folder (.claude/skills/pstack/upstream/skills/blast-radius in chmonitor/chmonitor) into .agents/skills/blast-radius in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blast-radius, .gemini/skills/blast-radius, .github/skills/blast-radius and .opencode/skills/blast-radius in your project.
SKILL.md names no scripts, command-line tools or credentials: Blast Radius is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Blast Radius is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Blast Radius: Data Breach Blast Radius (github/awesome-copilot, 40k stars), Blast Radius Check (cursor/plugins, 10k stars), Blast Radius (pedrohcgs/claude-code-my-workflow, 1.6k stars) and Blast Radius Drill (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 298 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.
Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.