Agent skill

Blast Radius

by pedrohcgs in pedrohcgs/claude-code-my-workflow

Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.

MITAuto-check: notes

Install Blast Radius

skills CLI
$ npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pedrohcgs/claude-code-my-workflow blast-radius --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/blast-radius .claude/skills/blast-radius && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blast-radius
GitHub stars
1.7k
Token cost
~1.5k tokens
SKILL.md length
810 words
Files
1
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.

  • Works in 6 steps: Enumerate consumers before editing → Name the contract you are about to change → Prefer changes that cannot break a… → …
  • Editing shared code
  • SKILL.md covers 1. Enumerate consumers before…, 2. Name the contract you are…, 3. Prefer changes that cannot… and 4. Run the consumers — end to…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Blast Radius is an agent skill from pedrohcgs/claude-code-my-workflow. Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Catches the change that looks purely additive but silently breaks a contract in a file you never opened. Use when editing shared code, adding a field/column/return element, renaming, changing units or defaults, or touching a pipeline that produces reported numbers.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A ready-to-fork Claude Code template for academics using LaTeX/Beamer + R. Multi-agent review, quality gates, adversarial QA, and replication protocols. The licence is MIT.

When your agent uses it

  • Editing shared code
  • Adding a field/column/return element
  • Touching a pipeline that produces reported numbers

Example prompts

  • “/blast-radius”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Write

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enumerate consumers before editing
  2. Name the contract you are about to change
  3. Prefer changes that cannot break a contract
  4. Run the consumers — end to end, on real inputs
  5. Green is uninformative if nothing ran
  6. Record the contract change

What it can do on your machine

Read from SKILL.md and the folder at commit ae72617. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blast Radius loads about 1.5k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 810 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pedrohcgs/claude-code-my-workflow at commit ae72617, republished under its MIT licence (© pedrohcgs). 810 words, ~1,524 tokens.

Download SKILL.mdSave it as .claude/skills/blast-radius/SKILL.md (or your agent's skills folder).
name
blast-radius
description
Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Catches the change that looks purely additive but silently breaks a contract in a file you never opened. Use when editing shared code, adding a field/column/return element, renaming, changing units or defaults, or touching a pipeline that produces reported numbers.
allowed-tools
Read, Grep, Glob, Bash, Write
metadata.protocol
bounded-delegation

Know the blast radius before you change it

The dangerous change is not the risky-looking one. It is the one that looks purely additive — adding a returned value, a column, an option — and quietly violates a contract three files away that nobody re-read. Compilation and type checks will not catch a positional or length contract; you get either a crash far from the edit, or worse, silently wrong output.

Rule: if you change a shared interface, run its consumers. Reading them is not running them.

1. Enumerate consumers before editing

Grep for every call site, import, and downstream reference — including tests, notebooks, scripts, docs, and anything that regenerates reported results. Note which ones produce numbers that appear in a paper, dashboard, or release: those are the ones where silent breakage is most costly.

If a consumer lives in another repo, another language, or a generated artifact, write it down now; you will not remember at verification time.

A consumer in another repo pins this one by commit SHA. Its verification receipt records the revision it was built against — not a branch, not a version string, both of which keep moving under it. So a change here that moves a number the downstream reports is not finished when this repo goes green: before/after evidence for what moved, regeneration of the downstream artifact, and the re-pin all belong to the same round as the change — release-engineering.md §6 has the ordering within it. A downstream left pinned to the old SHA is an honest, inspectable state; one pointed at a moving reference silently inherits a number nobody re-verified.

2. Name the contract you are about to change

Ask explicitly what downstream code is entitled to assume:

  • Arity / length — does anything index positionally, zip against a fixed list, or preallocate a matrix of known width? Adding an element breaks all three.
  • Names and order — does anything match by name, by position, or pair your output against a separate parallel list of labels?
  • Types, units, scale — dollars vs cents, rate vs percent, seconds vs ms, 0-indexed vs 1-indexed.
  • Nullability and sentinels — new empty/NA cases a consumer will not expect.
  • Defaults — changing a default silently changes every caller that relied on it.
  • Identity/ordering guarantees — row order, sort stability, key uniqueness.

The classic failure: a returned vector grows from 6 to 7, while a consumer pairs it against a hard-coded list of 6 labels. Nothing errors at the edit site; the consumer either throws far away or, worse, recycles and mislabels every row.

3. Prefer changes that cannot break a contract

Additive-and-named beats additive-and-positional. Where you control the consumer, match by name rather than position. Where you cannot, version the interface rather than widening it in place.

Do not "fix" a mismatch by deriving labels/config from the new data if the old labels were deliberately different — deliberate relabeling exists (display names differing from internal names), and auto-deriving silently changes published output.

Show full SKILL.md (326 more words)Show less

4. Run the consumers — end to end, on real inputs

A consumer that merely imports is not exercised. Run at least one full path per distinct consumer pattern, and prefer the one that regenerates reported numbers.

Then verify both directions:

  • The new thing works.
  • The old things are unchanged. Diff previously-reported outputs; anything that moved must have a reason you can state. If the change was supposed to be behavior-preserving, byte-identical or within a declared tolerance is the evidence — not "it ran".

5. Green is uninformative if nothing ran

Confirm the check actually executed and could have failed: a skipped test, a filtered-out case, an exception swallowed into a default, or a tolerance widened after the comparison are all indistinguishable from success in a log. Where the change is consequential, seed a defect and confirm the check goes red — a comparison that cannot fail is not evidence.

6. Record the contract change

If the interface genuinely changed, say so where consumers will look: a NEWS/CHANGELOG entry, a versioned interface note, or a comment at the definition naming what downstream code may assume. For anything reused or released, freeze inputs (versions, hashes, seeds) and record declared tolerances so the next comparison is reproducible rather than renegotiated.

Minimum checklist

  1. Grep all consumers, including tests, scripts, docs, other repos/languages.
  2. Write down the contract: arity, names, order, types, units, defaults, ordering.
  3. Make the change name-based/versioned where you can.
  4. Run at least one full path per consumer pattern.
  5. Diff previously-reported outputs; explain any movement.
  6. Seed a defect to prove the check can fail.
  7. Record the contract change where consumers will see it.
  8. Re-pin every cross-repo consumer to the new SHA — regenerated and re-verified in this round, not the next one.

Cross-references

© pedrohcgs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/blast-radius of pedrohcgs/claude-code-my-workflow.

Open the folder on GitHubat commit ae72617

Compare with similar skills

Blast Radius next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blast Radius compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blast Radius this skillpedrohcgs/claude-code-my-workflow1.7k—~1.5kAutomated safety check: NotesMIT
Data Breach Blast Radiusgithub/awesome-copilot40k1 repos~3.6kAutomated safety check: NotesMIT
Blast Radius Checkcursor/plugins11k9 repos~964Automated safety check: PassNone
Graph-Based Change Reviewtirth8205/code-review-graph32k1 repos~331Automated safety check: PassMIT
Make Changesremix-run/remix33k—~2.4kAutomated safety check: PassMIT
Orch Change Featureaffaan-m/ECC276k1 repos~420Automated safety check: PassMIT

Similar skills

  • Data Breach Blast Radius

    github/awesome-copilot

    Official

    Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

    40k GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check: notes
  • Blast Radius Check

    cursor/plugins

    Official

    Finds what a code change could break outside its diff and proves the single fact that makes it safe by running real code instead of writing an explanation.

    11k GitHub starsUsed in 9 repos~964 tokens
    DevelopmentAuto-check passed
  • Graph-Based Change Review

    tirth8205/code-review-graph

    Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.

    32k GitHub starsUsed in 1 repo~331 tokens
    DevelopmentAuto-check passed
  • Make Changes

    remix-run/remix

    Create or update Remix repo change files under packages//.changes.

    33k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Orchestrate altering an existing, working feature to new desired behavior — update its tests to the new spec, change the implementation to match, review, and gated commit.

    276k GitHub starsUsed in 1 repo~420 tokens
    Auto-check passed
  • Azure Functions

    davila7/claude-code-templates

    Expert patterns for Azure Functions development including isolated worker model, Durable Functions orchestration, cold start optimization, and production patterns.

    33k GitHub starsUsed in 2 repos~344 tokens
    Backend & APIsAuto-check passed

More from pedrohcgs/claude-code-my-workflow

All 59 skills in this repo
  • Devils Advocate

    pedrohcgs/claude-code-my-workflow

    Adversarial 5-7 question challenge to a deck's pedagogical choices — ordering, prerequisites, cognitive load, motivation.

    1.7k GitHub starsUsed in 2 repos~641 tokens
    Auto-check passed
  • Vaccinate

    pedrohcgs/claude-code-my-workflow

    Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.

    1.7k GitHub stars~2.1k tokensUpdated 12 days ago
    Auto-check: notes
  • Compile Latex

    pedrohcgs/claude-code-my-workflow

    Compile a Beamer LaTeX slide deck with XeLaTeX (3 passes + bibtex).

    1.7k GitHub starsUsed in 1 repo~492 tokens
    Auto-check: notes
  • Context Status

    pedrohcgs/claude-code-my-workflow

    Show current context status and session health. An agent skill from pedrohcgs/claude-code-my-workflow.

    1.7k GitHub starsUsed in 1 repo~613 tokens
    Auto-check: notes
  • Capture Environment

    pedrohcgs/claude-code-my-workflow

    Snapshot the computational environment for a replication package — detects the analysis stack (R / Stata / Python) and emits the right lockfiles (renv.lock + sessionInfo.txt, requirements.txt /…

    1.7k GitHub stars~2.8k tokensUpdated 12 days ago
    Auto-check: notes
  • Checkpoint

    pedrohcgs/claude-code-my-workflow

    Save a structured state snapshot before stopping or handing off.

    1.7k GitHub stars~2.8k tokensUpdated 12 days ago
    Auto-check: notes

Questions about Blast Radius

What does Blast Radius do?

Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them. Blast Radius is an agent skill from pedrohcgs/claude-code-my-workflow. Before and after changing anything shared — a function's return value, a signature, a schema, a label set, a config default, a constant, a file format — find every consumer and actually run them.

When should I use Blast Radius?

Blast Radius fits situations like: editing shared code; adding a field/column/return element; touching a pipeline that produces reported numbers.

How do I install Blast Radius in Claude Code?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a claude-code`. Or copy the skill folder (.claude/skills/blast-radius in pedrohcgs/claude-code-my-workflow) into .claude/skills/blast-radius in your project. Claude Code loads it when a task matches its description.

How do I install Blast Radius in Codex?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a codex`. Or copy the skill folder (.claude/skills/blast-radius in pedrohcgs/claude-code-my-workflow) into .agents/skills/blast-radius in your project. Codex loads it when a task matches its description.

Can I use Blast Radius in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pedrohcgs/claude-code-my-workflow --skill blast-radius -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blast-radius, .gemini/skills/blast-radius, .github/skills/blast-radius and .opencode/skills/blast-radius in your project.

What does Blast Radius need to run?

SKILL.md names no scripts, command-line tools or credentials: Blast Radius is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Write.

Does Blast Radius access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Blast Radius safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Blast Radius use?

Blast Radius is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blast Radius use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blast Radius?

Skills that share tags, products or a category with Blast Radius: Data Breach Blast Radius (github/awesome-copilot, 40k stars), Blast Radius Check (cursor/plugins, 11k stars), Graph-Based Change Review (tirth8205/code-review-graph, 32k stars) and Make Changes (remix-run/remix, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blast Radius?

pedrohcgs (a GitHub user) maintains it in pedrohcgs/claude-code-my-workflow, which has 1,655 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on September 27, 2026.

Source: pedrohcgs/claude-code-my-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.