Official agent skill

Data Breach Blast Radius

by github in github/awesome-copilot

Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

OfficialMITAuto-check: notesLegal & Compliance

Install Data Breach Blast Radius

skills CLI
$ npx skills add github/awesome-copilot --skill data-breach-blast-radius -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot data-breach-blast-radius --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-breach-blast-radius .claude/skills/data-breach-blast-radius && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-breach-blast-radius
GitHub stars
40k
Used in
1 other repo
Token cost
~3.6k tokens
SKILL.md length
1,589 words
Files
7 (incl. references)
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

  • Works in 7 steps: Scope & Stack Detection → Sensitive Data Inventory → Data Flow Tracing → …
  • Asked: assess breach impact
  • SKILL.md covers When to Activate, How This Skill Works, Execution Workflow and Output Rules, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Data Breach Blast Radius is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/SOURCES.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/SOURCES.md`, `references/blast-radius-calculator.md` and `references/data-classification.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, Healthcare and finance regulation and Security review. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Asked: assess breach impact
  • What data could be exposed
  • Calculate blast radius
  • Data exposure analysis

Example prompts

  • “assess breach impact”
  • “what data could be exposed”
  • “calculate blast radius”
  • “/data-breach-blast-radius”

Requirements

  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Scope & Stack Detection
  2. Sensitive Data Inventory
  3. Data Flow Tracing
  4. Blast Radius Calculation
  5. Regulatory Impact Estimation
  6. Blast Radius Report Generation
  7. Hardening Roadmap

What it can do on your machine

Read from SKILL.md and the folder at commit 7cce7cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • ibm.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Breach Blast Radius loads about 3.6k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,589 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~245
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~21k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:85
    - Environment files (`.env`, `.env.*`), config files, `appsettings.json`, `application.yml`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 7cce7cf, republished under its MIT licence (© github). 1,589 words, ~3,551 tokens.

Download SKILL.mdSave it as .claude/skills/data-breach-blast-radius/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
data-breach-blast-radius
description
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/SOURCES.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data exposure analysis", "how bad would a breach be", "quantify data risk", "sensitive data inventory", "data flow security audit", "pre-breach assessment", "worst-case breach scenario", "breach readiness", "data risk report", "/data-breach-blast-radius". For any stack handling user data, health records, or financial information. Output labels law-sourced figures (exact) vs heuristic estimates (planning only). Does not replace legal counsel.

Data Breach Blast Radius Analyzer

You are a Data Breach Impact Expert. Your mission is to answer the most important security question most teams never ask before a breach: "If we were breached right now, how bad would it be — and what would it cost us?"

This skill performs a proactive blast radius analysis: a full audit of what sensitive data your codebase handles, how it flows, where it could leak, how many people would be affected, and what regulatory consequences would follow — before any breach occurs.

Why this matters: 83% of organizations have experienced more than one data breach (IBM Cost of a Data Breach Report). The global average breach cost was $4.88M in 2024, with the 2025 IBM report showing a 9% decrease — download the current edition at https://www.ibm.com/reports/data-breach. Organizations that identify and remediate exposure points before a breach consistently face lower regulatory fines due to demonstrable due diligence.

What this skill produces vs. what is legally exact:

  • Legally exact: Regulatory fine maximums and breach notification timelines (sourced verbatim from GDPR Art. 83, CCPA § 1798.155, 45 CFR § 160.404, etc. — all cited in references/SOURCES.md)
  • Planning estimates: Blast radius scores, financial impact ranges, and record counts (heuristic models based on OWASP risk methodology and IBM benchmarks)
  • Always state in output: Which figures are law-sourced (exact) vs. model-derived (estimate)
  • Never replace qualified legal counsel or a formal DPIA/risk assessment

When to Activate

  • Auditing a codebase before a security review or pentest
  • Preparing a data processing impact assessment (DPIA)
  • Building or reviewing a disaster recovery / incident response plan
  • Onboarding a new system that handles customer data
  • Preparing for regulatory compliance (GDPR, CCPA, HIPAA, SOC 2)
  • Responding to "what's our exposure?" from engineering leadership
  • Any request mentioning: blast radius, breach impact, data exposure, sensitive data inventory, data risk, worst-case scenario
  • Direct invocation: /data-breach-blast-radius

How This Skill Works

Unlike tools that only find vulnerabilities, this skill quantifies business and regulatory impact:

  1. Discovers every sensitive data asset in the codebase (schemas, models, DTOs, logs, configs, API contracts)
  2. Classifies data into severity tiers (Tier 1–4) using global regulatory standards
  3. Traces data flows from ingestion → processing → storage → transmission → deletion
  4. Identifies all exposure vectors — where data could leak (API endpoints, logs, exports, caches, queues)
  5. Calculates the blast radius: estimated records affected, user population at risk, regulatory jurisdictions triggered
  6. Quantifies the regulatory impact (GDPR fines, CCPA penalties, HIPAA sanctions, breach notification costs)
  7. Generates a prioritized hardening roadmap ordered by impact-per-effort

Execution Workflow

Follow these steps in order every time:

Step 1 — Scope & Stack Detection

Determine what to analyze:

  • If a path was given (/data-breach-blast-radius src/), analyze that scope
  • If no path is given, analyze the entire project
  • Detect language(s) and frameworks (check package.json, requirements.txt, go.mod, pom.xml, Cargo.toml, Gemfile, composer.json, .csproj)
  • Identify the database layer (ORM models, schema files, migrations, Prisma schema, Entity Framework, Hibernate, SQLAlchemy, ActiveRecord)
  • Identify API layer (REST controllers, GraphQL schemas, gRPC proto files, OpenAPI specs)
  • Identify infrastructure-as-code (Terraform, Bicep, CloudFormation, Pulumi) for storage resource exposure

Read references/data-classification.md to load the full sensitivity tier taxonomy.


Step 2 — Sensitive Data Inventory

Scan ALL files for sensitive data definitions:

Data Model Layer:

  • Database schemas, migrations, ORM models, entity classes
  • GraphQL types, Prisma schema, TypeORM entities, Mongoose schemas
  • Identify every field that maps to a data category in references/data-classification.md
  • Note the table/collection name and estimated cardinality (if seeders, fixtures, or comments reveal scale)

API Contract Layer:

  • REST request/response DTOs and serializers
  • GraphQL query/mutation return types
  • gRPC proto message definitions
  • OpenAPI / Swagger spec fields
  • Flag fields that expose sensitive data externally

Configuration & Secrets:

  • Environment files (.env, .env.*), config files, appsettings.json, application.yml
  • Terraform/Bicep variable files and outputs
  • CI/CD pipeline files (.github/workflows/, .gitlab-ci.yml, Jenkinsfile, azure-pipelines.yml)
  • Docker/Kubernetes config maps and secrets

Log & Audit Layer:

  • Logging statements — identify what user data gets logged
  • Analytics/telemetry integrations (Segment, Mixpanel, Datadog, Sentry, Application Insights)
  • Audit log tables and event tracking

For each sensitive data field found, record:

| Field | Table/Source | Data Tier | Purpose | Encrypted? | Notes |

Classification basis: Tier assignments follow GDPR Article 9 (special categories), PCI-DSS v4.0, and HIPAA 45 CFR Part 164. See references/data-classification.md for the full taxonomy and references/SOURCES.md for primary source links.


Step 3 — Data Flow Tracing

Trace how sensitive data moves through the system:

Ingestion Points (data enters the system):

  • Form submissions, API POST/PUT endpoints, file uploads
  • Third-party webhooks, OAuth callbacks, SSO assertions
  • Data imports, CSV/Excel ingestion, ETL pipelines

Processing Points (data is used/transformed):

  • Business logic operating on sensitive fields
  • Caching layers (Redis, Memcached) — what keys contain PII?
  • Message queues (Kafka, SQS, Service Bus, RabbitMQ) — what payloads?
  • Background jobs and workers — what data do they process?

Storage Points (data at rest):

  • Primary databases (SQL, NoSQL, time-series)
  • File storage (S3, Azure Blob, GCS, local filesystem)
  • Search indexes (Elasticsearch, OpenSearch, Azure AI Search, Algolia) — are PII fields indexed?
  • Analytics warehouses (BigQuery, Snowflake, Redshift, Synapse) — are they scoped properly?
  • Backup stores — are backups encrypted and access-controlled?

Transmission Points (data leaves the system):

  • Outbound API calls to third parties (payment processors, email providers, analytics)
  • Webhook deliveries — what payload is sent?
  • Report/export generation (CSV, PDF, Excel downloads)
  • Email/SMS/push notifications — what data is included in the message body?

Exposure Points (data can reach unauthorized parties):

  • Public-facing API endpoints without authentication
  • Missing authorization checks (IDOR / BOLA vulnerabilities)
  • Overly broad API responses (returning more fields than needed)
  • CORS misconfigurations
  • Publicly accessible storage buckets or containers
  • Logging sensitive data to stdout/stderr in containerized environments
  • Error messages or stack traces containing PII
  • Debug endpoints left active in production

Read references/blast-radius-calculator.md for scoring formulas.


Show full SKILL.md (691 more words)Show less
Step 4 — Blast Radius Calculation

For each exposure vector identified in Step 3, calculate:

Blast Radius Score = Data Sensitivity Tier × Exposure Likelihood × Population Scale × Data Completeness

Population Scale Estimate:

  • If user counts are hard-coded (e.g., seeder files, comments, README): use that
  • If no count found: use a conservative estimate and state the assumption
    • SaaS product → assume 10K–1M users
    • Internal tool → assume 100–10K users
    • Consumer app → assume 100K–10M users
  • Apply a multiplier if the breach would expose data of minors (×2), health data (×3), or financial credentials (×5) due to regulatory severity

Regulatory Jurisdiction Detection:

  • If gdpr / EU currencies / EU phone formats / .eu domains / EU datacenter regions found → GDPR applies
  • If California residents mentioned / US .com / Stripe US / state-specific tax logic → CCPA applies
  • If health record fields (diagnosis, medication, ICD codes, FHIR resources) → HIPAA applies
  • If Brazilian users / BRL currency / CPF fields → LGPD applies
  • If Singapore / Thailand / Malaysia / Philippines data patterns → PDPA applies
  • Apply ALL jurisdictions that match — the most restrictive governs notification timeline

Read references/regulatory-impact.md for fine calculation formulas and notification requirements.


Step 5 — Regulatory Impact Estimation

For each triggered jurisdiction:

  • Calculate the maximum fine exposure using formulas in references/regulatory-impact.md
  • Calculate the minimum fine exposure (realistic for first offense with cooperation)
  • Estimate the breach notification cost (legal, communications, credit monitoring)
  • Estimate the reputational multiplier (public-facing breach vs. internal tool)

Generate a Financial Impact Summary Table:

| Regulation | Max Fine | Realistic Fine | Notification Cost | Timeline |

Note: These are estimates for risk planning purposes only. Always consult legal counsel for actual regulatory guidance.


Step 6 — Blast Radius Report Generation

Read references/report-format.md and generate the full report.

The report MUST include:

  1. Executive Summary (2–3 paragraphs, no jargon)
  2. Sensitive Data Inventory (table: all PII/PHI/financial/credential fields found)
  3. Data Flow Map (Mermaid diagram of data moving through the system)
    • After building the Mermaid markup, call renderMermaidDiagram with the markup and a short title so the diagram renders visually — do not output it as a fenced code block
    • Use style directives: fill:#ff4444 (red) for critical findings, fill:#ff8800 (orange) for high-severity exposure points
  4. Top 5 Exposure Vectors (ranked by blast radius score)
  5. Regulatory Blast Radius Table (per-jurisdiction)
  6. Financial Impact Estimate (realistic range)
  7. Hardening Roadmap (from references/hardening-playbook.md)

Step 7 — Hardening Roadmap

Read references/hardening-playbook.md and generate a prioritized action plan:

For each critical or high-severity exposure vector:

  • What to fix: specific code/config change
  • Why: regulatory risk and user impact
  • Effort: Low / Medium / High
  • Impact: blast radius reduction percentage (estimated)
  • Quick win flag: mark items fixable in < 1 day

Sort by: (Impact × Severity) / Effort — highest value first.


Output Rules

  • Always start with the Executive Summary — leadership reads this first
  • Always include the Sensitive Data Inventory table — this is the foundation
  • Always produce the Financial Impact Estimate — this drives organizational change
  • Always call renderMermaidDiagram for the Data Flow Map — never output raw Mermaid code blocks; the tool renders it as a visual diagram automatically
  • Never auto-apply any code changes — present the hardening roadmap for human review
  • Be specific — cite file paths, field names, and line numbers for every finding
  • State assumptions — if record count is estimated, say so explicitly
  • Be calibrated — distinguish "this is definitely exposed" from "this could be exposed under conditions X"
  • If the codebase has minimal sensitive data and strong controls, say so clearly and explain what was scanned

Severity Tiers for Blast Radius

TierLabelExamplesMultiplier
T1CatastrophicGovernment IDs, biometric data, health records, financial credentials, passwords×5
T2CriticalFull name + address + DOB combined, payment card data (PAN), SSN, passport numbers×4
T3HighEmail + password (hashed), phone numbers, precise geolocation, IP addresses, device fingerprints×3
T4ElevatedFirst name only, email address only, general location (city), usage analytics×2
T5StandardNon-personal config data, public content, anonymized aggregates×1

Reference Files

Load on-demand as needed:

FileUse WhenContent
references/data-classification.mdStep 2 — alwaysComplete taxonomy of PII, PHI, PCI-DSS, financial, credential, and behavioral data with detection patterns
references/blast-radius-calculator.mdStep 4Scoring formulas, population scale estimators, completeness multipliers, exposure likelihood matrix
references/regulatory-impact.mdStep 5GDPR/CCPA/HIPAA/LGPD/PDPA fine formulas, notification timelines, breach cost benchmarks, jurisdiction detection patterns
references/hardening-playbook.mdStep 7Prioritized controls: encryption, access control, data minimization, tokenization, audit logging, anonymization patterns by tech stack
references/report-format.mdStep 6Full report template with Mermaid data flow diagram syntax, financial summary table, hardening roadmap format

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/data-breach-blast-radius of github/awesome-copilot.

  • SKILL.md
  • references/SOURCES.md
  • references/blast-radius-calculator.md
  • references/data-classification.md
  • references/hardening-playbook.md
  • references/regulatory-impact.md
  • references/report-format.md

Open the folder on GitHubat commit 7cce7cf

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Data Breach Blast Radius next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Breach Blast Radius compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Breach Blast Radius this skillgithub/awesome-copilot40k1 repos~3.6kAutomated safety check: NotesMIT
Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT

Similar skills

  • Cursor Compliance Audit

    jeremylongshore/tons-of-skills-marketplace

    Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

    2.8k GitHub stars~2.3k tokensUpdated today
    Legal & ComplianceAuto-check: notes
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    942 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Data Breach Blast Radius

What does Data Breach Blast Radius do?

Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…. Data Breach Blast Radius is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art.

When should I use Data Breach Blast Radius?

Data Breach Blast Radius fits situations like: asked: assess breach impact; what data could be exposed; calculate blast radius; data exposure analysis.

How do I install Data Breach Blast Radius in Claude Code?

Run `npx skills add github/awesome-copilot --skill data-breach-blast-radius -a claude-code`. Or copy the skill folder (skills/data-breach-blast-radius in github/awesome-copilot) into .claude/skills/data-breach-blast-radius in your project. Claude Code loads it when a task matches its description.

How do I install Data Breach Blast Radius in Codex?

Run `npx skills add github/awesome-copilot --skill data-breach-blast-radius -a codex`. Or copy the skill folder (skills/data-breach-blast-radius in github/awesome-copilot) into .agents/skills/data-breach-blast-radius in your project. Codex loads it when a task matches its description.

Can I use Data Breach Blast Radius in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill data-breach-blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-breach-blast-radius, .gemini/skills/data-breach-blast-radius, .github/skills/data-breach-blast-radius and .opencode/skills/data-breach-blast-radius in your project.

What does Data Breach Blast Radius need to run?

SKILL.md names no scripts, command-line tools or credentials: Data Breach Blast Radius is instructions for the agent only. Our summary lists: Docker.

Does Data Breach Blast Radius access the network?

SKILL.md names 1 domain. As links in the text: ibm.com. This is read from the text; nothing was executed.

Is Data Breach Blast Radius safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Data Breach Blast Radius use?

Data Breach Blast Radius is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Breach Blast Radius use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18k tokens, read only when the agent opens those files.

What are the alternatives to Data Breach Blast Radius?

Skills that share tags, products or a category with Data Breach Blast Radius: Cursor Compliance Audit (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Breach Blast Radius?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,792 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 8, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.