blast-radius-drill
Run the worst-case drill before an agent goes autonomous — the 'if this agent were fully hijacked right now, what's the damage' walk-through, the containment controls (caps, kill-switch, reversibility, isolation), and the recovery plan
Install / Use
npx skills add mohitagw15856/pm-claude-skills --skill blast-radius-drillInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of blast-radius-drill
blast-radius-drill scores 85/100 on our quality scale, 1883rd of 4,658 Development & Engineering skills we index (top 41%).
Its SKILL.md is 6.4 KB long, well organised into 13 sections and no code examples: a thorough specification that gives an agent plenty to work with.
With 1,396 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 8 days ago, so blast-radius-drill is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
blast-radius-drill compared with similar skills
All 4 of these similar skills score higher than blast-radius-drill; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| blast-radius-drill (this skill)by mohitagw15856 | 85 | 1.4k | 8d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.8k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
Frequently asked questions
- How do I install blast-radius-drill?
- Run
npx skills add mohitagw15856/pm-claude-skills --skill blast-radius-drill. The install tabs above show the steps for each supported agent. - Which AI agents does blast-radius-drill work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is blast-radius-drill safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is blast-radius-drill still maintained?
- The repository was last updated 8 days ago, so blast-radius-drill is actively maintained.
Skill content
View source on GitHubname: blast-radius-drill description: "Run the worst-case drill before an agent goes autonomous — the 'if this agent were fully hijacked right now, what's the damage' walk-through, the containment controls (caps, kill-switch, reversibility, isolation), and the recovery plan. Use when asked what's the worst my agent could do, run a blast-radius assessment, prepare for an agent going rogue, or am I ready to let this run unattended. Produces the worst-case walk-through, the containment controls, the reversibility audit, and the incident-recovery runbook."
Blast Radius Drill Skill
Before an agent runs unattended, one question decides whether that's brave or reckless: if this agent were fully hijacked right now — every permission turned against you — what is the total damage? Most people never ask it, and find the answer during the incident. The drill asks it on purpose: walk the worst case through every capability, then build the containment that bounds it — caps that halt runaway loops, a kill-switch that stops it fast, reversibility so a bad run is undoable, and isolation so the damage can't spread. The goal isn't zero risk; it's bounded, recoverable risk, known in advance.
What This Skill Produces
- The worst-case walk-through — per capability, the maximum damage a fully-hijacked agent could do, made concrete
- The containment controls — the caps, halts, and isolation that bound each worst case
- The reversibility audit — which actions are undoable (and how) vs. irreversible (and thus gated or denied)
- The recovery runbook — the kill-switch, the "what did it do" audit trail, and the restore steps — decided while calm
Required Inputs
Ask for these if not provided:
- The agent's capabilities and environment — from the tool-permission-review inventory; the drill runs the worst case through each grant
- The autonomy scope — how long it runs unattended, how many actions between human checks (longer + more = larger blast radius to contain)
- What's reachable — the accounts, systems, data, and money the agent's permissions can touch; the worst case is bounded by reach
- The reversibility landscape — what's backed up, version-controlled, or restorable vs. what's gone-once-done (sent email, spent money, deleted-without-backup, public posts)
Framework: The Drill
- Assume total compromise, then walk each capability: not "will it misbehave" but "it is hijacked — now what." File access → what could it read (secrets?) and destroy (which directories?). Send → who could it mail, how many? Shell → that's everything, so the drill for shell is "the whole machine and everything it can reach." Network → what data could leave. Money/actions → what could it spend or commit. The walk-through makes each abstract permission a concrete worst case: "it could email our entire customer list" is a sentence that changes configurations.
- Bound the loops with caps: the runaway isn't always malicious — an agent stuck in a loop can send 400 emails, make 1,000 API calls, or delete a directory tree just as fast as a hijacked one. Every high-blast capability gets a cap (N actions/hour, M total, then halt-and-alert) so the worst case is bounded by the cap, not by how fast the agent runs. Uncapped autonomy is unbounded blast radius by definition.
- Reversibility is the safety net — audit it honestly: sort every possible action into undoable (file changes under git, drafts not sent, sandboxed operations — a bad run is
restore) and irreversible (sent email, spent money, public posts, deleted-without-backup, external API side effects). Irreversible actions either get denied for autonomous runs or gated to a human; reversible ones can flow, because the recovery cost is a restore. The drill's honesty: name what genuinely can't be undone and treat it accordingly. - Isolation contains the spread: the blast radius should stop at a boundary — an isolated environment (the browser/file sandbox), a dedicated account with limited reach, network egress limits. The difference between "the agent messed up its sandbox" and "the agent reached production" is isolation, decided before the run. A compromised agent contained to a scratch environment is a story; one with production reach is a postmortem.
- The recovery runbook exists before it's needed: the kill-switch (the exact step to stop it now — revoke the token, kill the process, flip the toggle), the audit trail (so "what did it actually do" is answerable in minutes, not forensically), and the restore steps per reversible-damage type. Written while calm, because the version composed during a runaway at 2am is a panic, and a bounded-but-unrecovered incident is still an incident.
Output Format
Blast Radius Drill: [agent] — autonomy: [scope] · env: [reach]
The Worst Case (per capability, assuming full compromise)
| Capability | Maximum damage | Concrete example | |---|---|---|
Containment Controls
[Caps per high-blast capability (rate + total + halt) · isolation boundary · egress limits]
Reversibility Audit
Undoable: [actions → how] · Irreversible: [actions → denied or human-gated for autonomous runs]
Recovery Runbook
[The kill-switch (exact step) · the audit trail (how to see what it did) · restore steps per damage type — written now]
The Verdict
[Ready for autonomy / gate these first / not yet — with the bounded-worst-case stated]
Quality Checks
- [ ] The worst case was walked assuming total compromise, made concrete per capability
- [ ] Every high-blast capability has a cap that halts
- [ ] Irreversible actions are denied or gated for autonomous runs
- [ ] An isolation boundary contains the spread
- [ ] The kill-switch, audit trail, and restore steps exist before go-live
Anti-Patterns
- [ ] Do not skip the drill because "it'll probably be fine" — the worst case is found during the incident by those who don't run it
- [ ] Do not run uncapped autonomy — unbounded actions is unbounded blast radius, hijack or bug alike
- [ ] Do not let irreversible actions flow unattended — undoable can flow; sent/spent/deleted-forever gates or denies
- [ ] Do not skip isolation — the boundary is the difference between a bad sandbox and a production breach
- [ ] Do not improvise recovery — the kill-switch composed mid-runaway is a panic; write it while calm
Related Skills
ai-job-search
44.8kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
