Data Breach Blast Radius
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/blast-radius .claude/skills/blast-radius && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .claude/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radiusType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/blast-radius .agents/skills/blast-radius && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .agents/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/blast-radius .cursor/skills/blast-radius && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .cursor/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pedrohcgs/claude-code-my-workflow.git --path .claude/skills/blast-radius--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/blast-radius .gemini/skills/blast-radius && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .gemini/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radiusInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/blast-radius .github/skills/blast-radius && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .github/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/blast-radius .opencode/skills/blast-radius && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "blast-radius" agent skill from https://github.com/pedrohcgs/claude-code-my-workflow/tree/main/.claude/skills/blast-radius into .opencode/skills/blast-radius/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blast-radius", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
blast-radiusBefore and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.
Blast Radius is an agent skill from pedrohcgs/claude-code-my-workflow. Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Catches the change that looks purely additive but silently breaks a contract in a file you never opened. Use when editing shared code, adding a field/column/return element, renaming, changing units or defaults, or touching a pipeline that produces reported numbers.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: A ready-to-fork Claude Code template for academics using LaTeX/Beamer + R. Multi-agent review, quality gates, adversarial QA, and replication protocols. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ae72617. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashWriteFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Blast Radius loads about 1.5k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 810 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from pedrohcgs/claude-code-my-workflow at commit ae72617, republished under its MIT licence (© pedrohcgs). 810 words, ~1,524 tokens.
.claude/skills/blast-radius/SKILL.md (or your agent's skills folder).The dangerous change is not the risky-looking one. It is the one that looks purely additive — adding a returned value, a column, an option — and quietly violates a contract three files away that nobody re-read. Compilation and type checks will not catch a positional or length contract; you get either a crash far from the edit, or worse, silently wrong output.
Rule: if you change a shared interface, run its consumers. Reading them is not running them.
Grep for every call site, import, and downstream reference — including tests, notebooks, scripts, docs, and anything that regenerates reported results. Note which ones produce numbers that appear in a paper, dashboard, or release: those are the ones where silent breakage is most costly.
If a consumer lives in another repo, another language, or a generated artifact, write it down now; you will not remember at verification time.
A consumer in another repo pins this one by commit SHA. Its verification receipt records the revision it was built against — not a branch, not a version string, both of which keep moving under it. So a change here that moves a number the downstream reports is not finished when this repo goes green: before/after evidence for what moved, regeneration of the downstream artifact, and the re-pin all belong to the same round as the change — release-engineering.md §6 has the ordering within it. A downstream left pinned to the old SHA is an honest, inspectable state; one pointed at a moving reference silently inherits a number nobody re-verified.
Ask explicitly what downstream code is entitled to assume:
The classic failure: a returned vector grows from 6 to 7, while a consumer pairs it against a hard-coded list of 6 labels. Nothing errors at the edit site; the consumer either throws far away or, worse, recycles and mislabels every row.
Additive-and-named beats additive-and-positional. Where you control the consumer, match by name rather than position. Where you cannot, version the interface rather than widening it in place.
Do not "fix" a mismatch by deriving labels/config from the new data if the old labels were deliberately different — deliberate relabeling exists (display names differing from internal names), and auto-deriving silently changes published output.
A consumer that merely imports is not exercised. Run at least one full path per distinct consumer pattern, and prefer the one that regenerates reported numbers.
Then verify both directions:
Confirm the check actually executed and could have failed: a skipped test, a filtered-out case, an exception swallowed into a default, or a tolerance widened after the comparison are all indistinguishable from success in a log. Where the change is consequential, seed a defect and confirm the check goes red — a comparison that cannot fail is not evidence.
If the interface genuinely changed, say so where consumers will look: a NEWS/CHANGELOG entry, a versioned interface note, or a comment at the definition naming what downstream code may assume. For anything reused or released, freeze inputs (versions, hashes, seeds) and record declared tolerances so the next comparison is reproducible rather than renegotiated.
verification-ladder.md — rung 2 (wiring)provenance-and-ground-truth.md — never re-bless a baseline in the commit that moves itrelease-engineering.md — pinning downstream consumers by SHA, and what a number-moving change owes them in the same round© pedrohcgs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/blast-radius of pedrohcgs/claude-code-my-workflow.
Open the folder on GitHubat commit ae72617
Blast Radius next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Blast Radius this skillpedrohcgs/claude-code-my-workflow | 1.7k | — | ~1.5k | Automated safety check: Notes | MIT | |
| Data Breach Blast Radiusgithub/awesome-copilot | 40k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Blast Radius Checkcursor/plugins | 11k | 9 repos | ~964 | Automated safety check: Pass | None | |
| Graph-Based Change Reviewtirth8205/code-review-graph | 32k | 1 repos | ~331 | Automated safety check: Pass | MIT | |
| Make Changesremix-run/remix | 33k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Orch Change Featureaffaan-m/ECC | 276k | 1 repos | ~420 | Automated safety check: Pass | MIT |
github/awesome-copilot
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…
cursor/plugins
Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.
tirth8205/code-review-graph
Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.
remix-run/remix
Create or update Remix repo change files under packages//.changes.
affaan-m/ECC
Orchestrate altering an existing, working feature to new desired behavior — update its tests to the new spec, change the implementation to match, review, and gated commit.
davila7/claude-code-templates
Expert patterns for Azure Functions development including isolated worker model, Durable Functions orchestration, cold start optimization, and production patterns.
pedrohcgs/claude-code-my-workflow
Adversarial 5-7 question challenge to a deck's pedagogical choices — ordering, prerequisites, cognitive load, motivation.
pedrohcgs/claude-code-my-workflow
Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.
pedrohcgs/claude-code-my-workflow
Compile a Beamer LaTeX slide deck with XeLaTeX (3 passes + bibtex).
pedrohcgs/claude-code-my-workflow
Show current context status and session health. An agent skill from pedrohcgs/claude-code-my-workflow.
pedrohcgs/claude-code-my-workflow
Snapshot the computational environment for a replication package — detects the analysis stack (R / Stata / Python) and emits the right lockfiles (renv.lock + sessionInfo.txt, requirements.txt /…
pedrohcgs/claude-code-my-workflow
Save a structured state snapshot before stopping or handing off.
Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Blast Radius is an agent skill from pedrohcgs/claude-code-my-workflow. Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.
Blast Radius fits situations like: editing shared code; adding a field/column/return element; touching a pipeline that produces reported numbers.
Run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a claude-code`. Or copy the skill folder (.claude/skills/blast-radius in pedrohcgs/claude-code-my-workflow) into .claude/skills/blast-radius in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a codex`. Or copy the skill folder (.claude/skills/blast-radius in pedrohcgs/claude-code-my-workflow) into .agents/skills/blast-radius in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blast-radius, .gemini/skills/blast-radius, .github/skills/blast-radius and .opencode/skills/blast-radius in your project.
SKILL.md names no scripts, command-line tools or credentials: Blast Radius is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Write.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Blast Radius is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Blast Radius: Data Breach Blast Radius (github/awesome-copilot, 40k stars), Blast Radius Check (cursor/plugins, 11k stars), Graph-Based Change Review (tirth8205/code-review-graph, 32k stars) and Make Changes (remix-run/remix, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pedrohcgs (a GitHub user) maintains it in pedrohcgs/claude-code-my-workflow, which has 1,655 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on September 27, 2026.
Source: pedrohcgs/claude-code-my-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.