Skip to content
DarkPrint
Aautogenblast-radius-check1.0.0

Blast Radius Check

Get card

Clone

npx -y darkprint clone blast-radius-check@1.0.0

There is no repository and no history behind a card. Download hands you the document as it stands, and Clone fetches the same document by name.

↓ 1 downloads

Expand the drafted mitigation into the concrete set of hosts and services it would touch, hold back anything wider than the declared limit, and emit the risk verdict the escalation path reads.

used in 1 blueprint

Specification

133 words · handed to the agent

Read the proposed mitigation on draft and expand every target expression in it, globs, tags, service names, into the concrete list of hosts and services it would touch, resolving them against live inventory rather than trusting the count the draft claims for itself. Measure that resolved list against two limits: at most twelve affected hosts, and nothing that belongs to tier-0 or to payments. Emit your verdict on risk, and put the mitigation on mitigation with the resolved target list attached only when it sits inside both limits. Treat a target you cannot resolve as over the limit, not as safe, and never widen or narrow the mitigation to make it fit, you judge it, you do not edit it. You are done when a verdict is on risk, whichever way it went.

Interfaces

1 in · 2 out

Inputs

1
Inputs declared by this node card
NameData typeRequiredDescription
draftjson requiredThe proposed mitigation as the composer wrote it, before anything has run.

Outputs

2
Outputs declared by this node card
NameData typeDescription
mitigationjsonThe mitigation cleared to run, with its resolved target list attached.
riskstatusThe risk verdict, what routes a mitigation to on-call instead of to the host.

Dependencies

1

The upstream nodes this card expects to receive from. Whenever a blueprint pins this card, each name is checked against a real edge in that graph. A name without a link is not a published card; it refers to a node inside some graph.

Card values

19 declared

Who the node is. The id is the key the DOT pins.

id
blast-radius-check
name
Blast Radius Check
type
validation
phases
Testing
Behaviourcard spec →

What it does, and the prose the agent is handed when the graph runs.

action32 words
Expand the drafted mitigation into the concrete set of hosts and services it would touch, hold back anything wider than the declared limit, and emit the risk verdict the escalation path reads.
spec133 words
Read the proposed mitigation on draft and expand every target expression in it, globs, tags, service names, into the concrete list of hosts and services it would touch, resolving them against live inventory rather than trusting the count the draft claims for itself. Measure that resolved list against two limits: at most twelve affected hosts, and nothing that belongs to tier-0 or to payments. Emit your verdict on risk, and put the mitigation on mitigation with the resolved target list attached only when it sits inside both limits. Treat a target you cannot resolve as over the limit, not as safe, and never widen or narrow the mitigation to make it fit, you judge it, you do not edit it. You are done when a verdict is on risk, whichever way it went.in full above
model
claude-opus-5
agent
Blast-radius QA
skill
skills/blast-radius-check.md
tools
HTTP fetch
mcp
fetch
params
protected_tiers: ["tier-0","payments"], max_affected_hosts: 12
Interfacescard spec →

What arrives, what leaves, which nodes it expects to hear from, and what may not.

inputs
draft : json
outputs
mitigation : json, risk : status
dependencies
resolution-composer
cannot
no type is refused
will_not
edit the mitigation it judges, clear a target it could not resolve
Evaluation metadatacard spec →

The keys the static analysis reads. Nothing here instructs the agent.

risk_markers
none
notes80 words
It reads live inventory over HTTP to expand the target set, which is the only reason this node reaches the network at all. The core vocabulary has no metrics or observability capability, so http-fetch stands in for the metrics API. That tool is what makes the analyzer infer unvalidated-external-access here: this node is itself the validation step, and doc 3 §4.1 will not let a node vouch for its own fetch, so the inference is correct and is left standing.
Service fieldscard spec →

The card's own version, and who wrote it.

version
1.0.0
author
autogen
provenance
not stated

Definitions for every card field

Version history

1 version published
  1. blast-radius-check@1.0.0currentsha256:bc769a71d976c28535872f677b6a8d6814f4ab75ff7865e5bfd143fbb6827027

    pinned byIncident Commanderautogen/incident-commander

A digest is a fingerprint (SHA-256) of the card's content, computed without the author and provenance fields. The same card from two people gets the same digest; any edit gets a new one.

First published version, so there is nothing to compare yet. Versions are never edited in place: the next change arrives as a new version, and the differences between the two documents are listed here.

Community notes (0)

No notes yet.

Nobody has posted about this node card yet.

Sign in to post a note.