Official agent skill

Blast Radius Check

by cursor in cursor/plugins

Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.

OfficialNo licenceAuto-check passedDevelopment

Install Blast Radius Check

skills CLI
$ npx skills add cursor/plugins --skill blast-radius -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cursor/plugins blast-radius --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cursor/plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pstack/skills/blast-radius .claude/skills/blast-radius && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blast-radius
GitHub stars
10k
Used in
9 other repos
Token cost
~964 tokens
SKILL.md length
639 words
Files
1
Skills in repo
99
Repo updated
First seen
Licence
None found

At a glance

Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.

  • Works in 5 steps: You said so. Worthless on its own. → You pointed at the line. A real… → You showed the bad case can't happen.… → …
  • Asking what a change could break somewhere else before it ships
  • SKILL.md covers Don't trust your own writeup, Steps and What to hand back
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill treats a convincing written analysis as worthless on its own, since it reads well whether or not it is true. The agent therefore finds the one or two facts a change's safety depends on and proves them. A five-step confidence ladder runs from simply saying so, through pointing at a real `file:line` and walking the failure case by hand, to running a script or test against the real code and reproducing the problem in the running app.

Listing callers is not the goal, since grep does that. The agent reads the change including behavior the diff does not spell out, looks for the single fact it is safe because of, and then checks where symbol search stops: the library's own source, its pinned version or local patches, timing such as microtasks and teardown, and data crossing boundaries such as API JSON, database columns, wire formats and feature flags. Often one small script that imports the shipped library settles it.

When your agent uses it

  • Asking what a change could break somewhere else before it ships
  • Reviewing a small diff that looks harmless but that you do not trust
  • Checking a risky dependency or caching change with a quick script

Example prompts

  • “What is the blast radius of switching the session cache to the new library?”
  • “Review this three-line diff and prove it cannot break the logout flow.”
  • “What could this change to the date parser break in the API responses?”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. You said so. Worthless on its own.
  2. You pointed at the line. A real file:line, or the library's own source.
  3. You showed the bad case can't happen. You walked the failure step by step and it doesn't reach.
  4. You ran it. A script or test that calls the real code and fails loud if you're wrong.
  5. You reproduced it in the running app.

What it can do on your machine

Read from SKILL.md and the folder at commit 9f451cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blast Radius Check loads about 964 tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 639 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~964

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 639 words (~964 tokens).

“Find what a change breaks somewhere else, before it ships. Use for "blast radius of X", "what could this break", or reviewing a small diff you don't trust yet.”

— opening of SKILL.md by cursor
name
blast-radius
disable-model-invocation
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in pstack/skills/blast-radius of cursor/plugins.

Open the folder on GitHubat commit 9f451cf

Used in 9 other repositories

We found 9 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 9 other GitHub owners. This page covers the copy in cursor/plugins, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Blast Radius Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blast Radius Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blast Radius Check this skillcursor/plugins10k9 repos~964Automated safety check: PassNone
Docs GuardamElnagdy/guard-skills1.3k—~2.1kAutomated safety check: PassMIT
Pre-Merge Checkjsmastery-pro/skills1.4k—~1.1kAutomated safety check: NotesMIT
Post-Feature Reviewjsmastery-pro/jsm-agent-skill216—~1.3kAutomated safety check: PassMIT
System1-Agents Self-ReviewThinkFlowLab/system1-agents120—~2kAutomated safety check: PassApache-2.0
Loop Change Verifiercobusgreyling/loop-engineering11k1 repos~383Automated safety check: PassMIT

Similar skills

  • Docs Guard

    amElnagdy/guard-skills

    Checks generated or edited documentation against the source code, flagging invented symbols, outdated samples and unverifiable claims before publishing.

    1.3k GitHub stars~2.1k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Pre-Merge Check

    jsmastery-pro/skills

    A gate before merge: verify runs the real app against the spec, and review has a different model do a senior code review, without editing code.

    1.4k GitHub stars~1.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Post-Feature Review

    jsmastery-pro/jsm-agent-skill

    Compares a finished feature with its plan, the project's architecture and design rules, and production-readiness checks, then reports issues without fixing them.

    216 GitHub stars~1.3k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • System1-Agents Self-Review

    ThinkFlowLab/system1-agents

    Prepares a local self-review report for a System1-Agents change before a PR is opened, checking the full diff, tests, docs, artifacts and claims against evidence.

    120 GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Loop Change Verifier

    cobusgreyling/loop-engineering

    Acts as a skeptical checker for changes an implementer sub-agent made, running the tests, confirming the diff scope and returning approve, reject or escalate to a human.

    11k GitHub starsUsed in 1 repo~383 tokens
    Agent WorkflowsAuto-check passed
  • Adversarial Review Before Shipping

    oaustegard/claude-skills

    Has a fresh-context adversary attack a blog post, recommendation, analysis brief or piece of code before you ship it, using a profile suited to that kind of artifact.

    150 GitHub stars~3.4k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed

More from cursor/plugins

All 99 skills in this repo
  • Official

    Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.

    10k GitHub starsUsed in 9 repos~1.6k tokens
    Auto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    Auto-check passed
  • Official

    Starts three parallel reviewer subagents over the current conversation transcript, then turns their findings into concrete edits to existing skills.

    10k GitHub starsUsed in 5 repos~1.2k tokens
    Auto-check passed
  • Official

    Applies four layers of technical-writing rules to docs, RFCs, readmes, PR descriptions and commit messages so a tired engineer follows them on the first read.

    10k GitHub starsUsed in 10 repos~2.4k tokens
    Auto-check passed
  • Advisor Mode

    cursor/plugins

    Official

    Adds a second, stronger model that the main agent consults before major decisions, when stuck and before finishing, controlled by /advisor commands.

    10k GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Official

    Prepare PRs for review by cleaning noisy history, improving PR descriptions, and adding reviewer guidance without changing code behavior.

    10k GitHub starsUsed in 3 repos~569 tokens
    Auto-check passed

Categories

Questions about Blast Radius Check

What does Blast Radius Check do?

Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation. The skill treats a convincing written analysis as worthless on its own, since it reads well whether or not it is true. The agent therefore finds the one or two facts a change's safety depends on and proves them.

When should I use Blast Radius Check?

Blast Radius Check fits situations like: asking what a change could break somewhere else before it ships; reviewing a small diff that looks harmless but that you do not trust; checking a risky dependency or caching change with a quick script.

How do I install Blast Radius Check in Claude Code?

Run `npx skills add cursor/plugins --skill blast-radius -a claude-code`. Or copy the skill folder (pstack/skills/blast-radius in cursor/plugins) into .claude/skills/blast-radius in your project. Claude Code loads it when a task matches its description.

How do I install Blast Radius Check in Codex?

Run `npx skills add cursor/plugins --skill blast-radius -a codex`. Or copy the skill folder (pstack/skills/blast-radius in cursor/plugins) into .agents/skills/blast-radius in your project. Codex loads it when a task matches its description.

Can I use Blast Radius Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cursor/plugins --skill blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blast-radius, .gemini/skills/blast-radius, .github/skills/blast-radius and .opencode/skills/blast-radius in your project.

What does Blast Radius Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Blast Radius Check is instructions for the agent only.

Does Blast Radius Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Blast Radius Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Blast Radius Check use?

No licence was found for Blast Radius Check or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Blast Radius Check use?

About 964 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blast Radius Check?

Skills that share tags, products or a category with Blast Radius Check: Docs Guard (amElnagdy/guard-skills, 1.3k stars), Pre-Merge Check (jsmastery-pro/skills, 1.4k stars), Post-Feature Review (jsmastery-pro/jsm-agent-skill, 216 stars) and System1-Agents Self-Review (ThinkFlowLab/system1-agents, 120 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blast Radius Check?

cursor (a GitHub organization, an official publisher) maintains it in cursor/plugins, which has 10,130 GitHub stars. The repository holds 99 skills in this directory. The repository was last updated on October 6, 2026.

Source: cursor/plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.