Review agent · Infra & pipeline

Blast radius & data exposure

Assesses how much damage a compromise of this code could cause, and how to shrink it.

svc/export.py1s3 = boto3.client("s3",2 aws_access_key_id=ADMIN_KEY)34@app.get("/export/all")Blastwhat this review answersCredentials broader than the task?Bulk export of sensitive data?What else would this unlock?$ verdict REAL ISSUE$ fix least-privilege, scoped data access▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Every other agent asks 'is there a hole?'. This one asks 'if there is, how bad is it?'. An over-privileged token turns a small bug into a full breach.

Thinking in blast radius is how mature teams prioritize: least privilege limits the cost of the bugs you haven't found yet.

What it checks

  • Over-privileged tokens and credentials
  • Components with broader data access than their task needs
  • Endpoints that can bulk-export sensitive data
  • Secrets that would unlock further systems

When it marks a finding as a likely false positive

  • Access is already scoped to the minimum the task needs

The fix it suggests

  • Least-privilege credentials
  • Scoping data access
  • Rate and volume limits on exports; segmenting secrets

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Why doesn't this agent have CWEs?

Blast radius is a lens rather than a bug class, so findings reach it by keywords such as wildcard permissions or bulk export.

Related agents

  • Infrastructure & IaC — Reviews Terraform, Helm, Ansible and server config for insecure defaults and exposure.
  • Cloud security — Checks cloud resources for public exposure, wildcard IAM and long-lived keys.
  • Container & Kubernetes — Checks Dockerfiles and Kubernetes manifests for root, privileged and host-level access.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Blast radius & data exposure agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free