Get card
Download
blast-radius-check@1.0.0.yamlClone
npx -y darkprint clone blast-radius-check@1.0.0There is no repository and no history behind a card. Download hands you the document as it stands, and Clone fetches the same document by name.
Expand the drafted mitigation into the concrete set of hosts and services it would touch, hold back anything wider than the declared limit, and emit the risk verdict the escalation path reads.
used in 1 blueprint
Specification
133 words · handed to the agentRead the proposed mitigation on draft and expand every target expression in it, globs, tags, service names, into the concrete list of hosts and services it would touch, resolving them against live inventory rather than trusting the count the draft claims for itself. Measure that resolved list against two limits: at most twelve affected hosts, and nothing that belongs to tier-0 or to payments. Emit your verdict on risk, and put the mitigation on mitigation with the resolved target list attached only when it sits inside both limits. Treat a target you cannot resolve as over the limit, not as safe, and never widen or narrow the mitigation to make it fit, you judge it, you do not edit it. You are done when a verdict is on risk, whichever way it went.
Interfaces
1 in · 2 outInputs
1| Name | Data type | Required | Description |
|---|---|---|---|
| draft | json | required | The proposed mitigation as the composer wrote it, before anything has run. |
Outputs
2Dependencies
1The upstream nodes this card expects to receive from. Whenever a blueprint pins this card, each name is checked against a real edge in that graph. A name without a link is not a published card; it refers to a node inside some graph.
Card values
19 declaredWho the node is. The id is the key the DOT pins.
- id
- blast-radius-check
- name
- Blast Radius Check
- type
- validation
- phases
- Testing
What it does, and the prose the agent is handed when the graph runs.
- action32 words
- Expand the drafted mitigation into the concrete set of hosts and services it would touch, hold back anything wider than the declared limit, and emit the risk verdict the escalation path reads.
- spec133 words
- Read the proposed mitigation on
draftand expand every target expression in it, globs, tags, service names, into the concrete list of hosts and services it would touch, resolving them against live inventory rather than trusting the count the draft claims for itself. Measure that resolved list against two limits: at most twelve affected hosts, and nothing that belongs totier-0or topayments. Emit your verdict onrisk, and put the mitigation onmitigationwith the resolved target list attached only when it sits inside both limits. Treat a target you cannot resolve as over the limit, not as safe, and never widen or narrow the mitigation to make it fit, you judge it, you do not edit it. You are done when a verdict is onrisk, whichever way it went.in full above - model
- claude-opus-5
- agent
- Blast-radius QA
- skill
- skills/blast-radius-check.md
- tools
- HTTP fetch
- mcp
- fetch
- params
- protected_tiers: ["tier-0","payments"], max_affected_hosts: 12
What arrives, what leaves, which nodes it expects to hear from, and what may not.
- inputs
- draft : json
- outputs
- mitigation : json, risk : status
- dependencies
- resolution-composer
- cannot
- no type is refused
- will_not
- edit the mitigation it judges, clear a target it could not resolve
The keys the static analysis reads. Nothing here instructs the agent.
- risk_markers
- none
- notes80 words
- It reads live inventory over HTTP to expand the target set, which is the only reason this node reaches the network at all. The core vocabulary has no metrics or observability capability, so
http-fetchstands in for the metrics API. That tool is what makes the analyzer inferunvalidated-external-accesshere: this node is itself the validation step, and doc 3 §4.1 will not let a node vouch for its own fetch, so the inference is correct and is left standing.
The card's own version, and who wrote it.
- version
- 1.0.0
- author
- autogen
- provenance
- not stated
Version history
1 version published- blast-radius-check@1.0.0currentsha256:bc769a71d976c28535872f677b6a8d6814f4ab75ff7865e5bfd143fbb6827027
pinned byIncident Commander
autogen/incident-commander
A digest is a fingerprint (SHA-256) of the card's content, computed without the author and provenance fields. The same card from two people gets the same digest; any edit gets a new one.
First published version, so there is nothing to compare yet. Versions are never edited in place: the next change arrives as a new version, and the differences between the two documents are listed here.
Community notes (0)
No notes yet.
Nobody has posted about this node card yet.
Sign in to post a note.