Repository navigation
Add blast-radius skill - #1776
kishormorol wants to merge 3 commits into
Conversation
A checklist for the moment before a bulk or destructive write — archiving users, revoking access, deleting rows, mailing a batch. It covers the gap between a query being right about rows and a bulk operation being right about the world. Its core move is to classify every affected row into act / exclude / unknown before touching any of them, where unknown is never act, and to check the act bucket for people the rule was never meant to catch. Every example is a real near-miss from running an internal platform: archiving on "no account on our chat platform" would have caught the research director, because that signal measured joining rather than working; revoking 98 apparently-stale permission grants would have cut off the service account and the team leads, since only 18 were genuinely stale; and one batch email would have rotated a token and invalidated an accept link the recipient already held. Apache-2.0, matching the repo's per-skill LICENSE.txt convention.
… hook The six ways a signal lies now open the skill rather than sitting inside step one, and each is named so it travels without the skill loaded: absence is not departure, ghost activity, the field changed meaning, status lags the artifact, clustered timestamps, loose matching invents members. Adds a PreToolUse hook, because a skill about not trusting a query only helps if it loads — and the agent that would blindly run the query is the one that will not think to load it. The hook fires on the command instead: ask for writes with no filter at all, checklist as context for filtered bulk writes and writes inside loops, silent for dry runs and read-only commands. Fails open on any error.
|
Thanks — reviewed at head Spec + repo conventions
Hook smoke battery — 19 cases against the extracted tree (byte-identical to
Precision edges in the matcher (suggestions only — both fail in the safe direction):
For author / maintainers
The skill content itself reads well — the signal-failure taxonomy and act/exclude/unknown framing are genuinely useful, and it is all instructions. No blocking issues from my side once the description/hook questions above are settled. |
…two matcher edges Review feedback on anthropics#1776. Move hooks/blast-radius.sh to scripts/blast-radius.sh. `hooks/` had no precedent under skills/ — eight skills already use scripts/ — and the name implied the file loads itself, which it does not. Document that. SKILL.md gains an "Installing the guard as a hook" section with the settings.json wiring, what each class of command produces, and the fail-open behaviour, so nobody has to infer the install path from the folder name. Fix two precision edges in the matcher, both of which failed safe but were wrong: - Only the first leading VAR=value assignment was stripped, because a sed '^' anchor cannot re-match after its own substitution. `FOO=1 BAR=2 rg ...` resolved to `BAR=2` and lost the read-only fast path. Scan the fields instead and take the first that is not an assignment. - Stripping from '#' to end of line was quote-unaware, so a '#' inside a string literal truncated the scan: `node -e "const c=('#fff'); db.users.deleteMany({})"` went silent. It also contradicted the note directly above it about not stripping string literals. Drop whole-line comments only. Normalise LICENSE.txt to the copy the other thirteen skills carry, filling the `Copyright [yyyy] [name of copyright owner]` appendix placeholder. Smoke battery: 19/19, including both edges above. quick_validate.py reports valid. Co-Authored-By: Kishor Morol <[email protected]>
|
Thanks for the detailed pass — all five points addressed in Hook moved to Re-ran your battery plus the two edges: 19/19. |
Keeps this repo in sync with anthropics/skills#1776, where review asked for all three changes. Move hooks/blast-radius.sh to scripts/blast-radius.sh. `hooks/` implied the file loads itself, which it does not — hooks are wired through settings — and upstream already uses scripts/ for skill aux files. README install snippets updated. SKILL.md gains an "Installing the guard as a hook" section, so the skill carries the settings.json wiring itself rather than relying on this README. Fix two precision edges in the matcher, both of which failed safe but were wrong: - Only the first leading VAR=value assignment was stripped, because a sed '^' anchor cannot re-match after its own substitution. `FOO=1 BAR=2 rg ...` resolved to `BAR=2` and lost the read-only fast path. Scan the fields instead and take the first that is not an assignment. - Stripping from '#' to end of line was quote-unaware, so a '#' inside a string literal truncated the scan: `node -e "const c=('#fff'); db.users.deleteMany({})"` went silent. It also contradicted the note directly above it about not stripping string literals. Drop whole-line comments only. Smoke battery: 19/19, including both edges above. Co-Authored-By: Kishor Morol <[email protected]>
Keeps blast-radius installable from this fork's marketplace while anthropics#1776 is still open upstream. The PR branch is untouched. Co-Authored-By: Kishor Morol <[email protected]>
|
Re-verified at head ✅ Env-assignment strip: Fail-open holds (empty |
|
Thanks for the thorough re-verification — really appreciate you running the full battery against the extracted tree. Leaving this open for maintainer review. |
What
blast-radius— a checklist for the moment before a bulk or destructive write:archiving users, revoking access, deleting rows, mailing a batch.
It covers the gap between a query being right about rows and a bulk operation being
right about the world. The core move is to classify every affected row into
act / exclude / unknown before touching any of them, where unknown is never act,
then check the act bucket for people the rule was never meant to catch.
Why
Every example in the skill is a real near-miss from running an internal platform, not an
invented scenario:
research director and a physician hired three weeks earlier. That signal measured
never joined, not left — of 505 active members, exactly one had ever left.
the team leads. Classified, only 18 were genuinely stale.
token and invalidating the accept link already in their inbox — their status field
said otherwise.
auto-generated drafts.
None of these were caught by being careful. They were caught by splitting a count into
named rows before trusting it.
Contents
scripts/blast-radius.shis opt-in and does nothing on its own — hooks load fromsettings, not from the skill folder, so SKILL.md carries the
settings.jsonwiring. Itexists because of the trigger problem: a skill about not trusting a query only helps if
it loads, and the agent that would blindly run the query is the one that will not think
to load it. An unfiltered write returns
permissionDecision: "ask"; a filtered bulkwrite returns the checklist as
additionalContext; read-only commands and anythingalready flagged
--dry-runstay silent. It fails open — missingjq, unrecognisedinput or any error exits
0silently.The skill is useful without it; drop the script if you would rather
skills/stayinstructions-only.
Notes
skills/— SKILL.md + LICENSE.txt, withaux files under
scripts/as eight other skills do.python3 skills/skill-creator/scripts/quick_validate.py skills/blast-radius→ valid.fast paths, multiple leading
VAR=valueassignments,#inside string literals,malformed input and output shape.
Happy to rename, trim, or restructure to fit house style.