- Home
- Skills
- Code Quality & Review
- PR Blast Radius Auditor
More screenshots
Works with the AI tools you already use
PR Blast Radius Auditor
Trace what a pull request can break and produce targeted merge evidence.
$19.99
PR Blast Radius Auditor
Example session with this skill installed
Audit this PR before merge. It changes packages/auth/token.ts and services/api/auth-middleware.ts. The shared parser will now reject tokens with our legacy issuer. services/refund-worker imports the same auth package, but it is absent from the changed files. We have API unit tests, no worker replay test, no issuer telemetry, and rollback currently means redeploying the previous auth package. Produce the dependency cone, material findings, targeted test matrix, and verdict.
- Read your context and instructions
- Compiled the pr blast radius
Verdict — TARGETED-VERIFICATION-REQUIRED
The change crosses a shared authentication contract and can affect a refund worker that is not visible in the diff. The blast radius is bounded enough to test, but merge evidence is incomplete because legacy-issuer traffic and the worker consumer are not covered.
Changed-surface ledger
| Changed path | Classification | Boundary |
|---|---|---|
| packages/auth/token.ts | shared runtime logic | issuer acceptance contract |
| services/api/auth-middleware.ts | API integration | authenticated request behavior |
Dependency and boundary map
token.ts → shared auth package → API middleware and refund worker. The material boundary is token issuer acceptance. Rejecting a previously accepted issuer is externally observable even if the parser signature is unchanged.
Material finding
HIGH — Refund worker may reject valid legacy tokens. Evidence: the shared import is observed; the volume of legacy issuers is unknown. Failure mechanism: the worker receives the same tokens but lacks a replay test. Required test: replay current and legacy issuer fixtures through both API and worker consumers. Owner question: which service owns issuer retirement? Rollback: retain the previous auth package as a deployable artifact until production issuer evidence is available.
Must-test matrix
- Current issuer through API and refund worker — proves the retained path.
- Legacy issuer through both consumers — directly discriminates the compatibility risk.
- Mixed-version deploy — checks whether old and new workers can coexist.
- Rollback smoke test using the previous package — proves reversal is operational, not theoretical.
Unknowns
Legacy-issuer frequency, mobile or external token issuers, worker replay coverage, and issuer-specific telemetry remain unknown. Absence of a failing test is not evidence of safety.
Validator boundary
The structured demonstration contains all six coverage domains and passes the bundled schema validator. This validates completeness of the record only; no repository or runtime test was executed in this demonstration.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
A local diff can break a distant system. Changed lines rarely show the complete impact of a pull request: shared parsers, event payloads, configuration keys, persisted formats, build artifacts, and deployment assumptions can affect workers and clients that never appear in the diff.
PR Blast Radius Auditor converts repository evidence into a bounded dependency cone. It classifies changed surfaces, traces direct and indirect consumers, identifies runtime, contract, state, build, observability, and rollback risks, then chooses the smallest tests that can confirm or falsify each material finding.
Built for backend, platform, monorepo, and release engineers reviewing shared libraries, APIs, events, migrations, background jobs, and cross-service pull requests. It profiles the repository's own framework, test runner, package graph, job adapter, ORM, and deployment conventions before applying the audit.
What the buyer receives
- Merge-evidence verdict
- Changed-surface ledger
- Dependency and boundary map
- Severity-ranked findings with observed, inferred, and unknown evidence separated
- Targeted must-test matrix
- Owner questions and unresolved evidence
- Rollback proof plan
- Deterministic JSON validation
The package includes the complete Skill source, domain method, worked audit, validator, mutation tests, expected-output example, trigger tests, and a six-page Buyer Guide PDF.
Boundaries
The Skill analyzes buyer-supplied or locally visible artifacts. It does not edit code, approve, merge, push, deploy, or contact owners. A passing validator proves record coverage, not runtime safety.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install