Skip to content
ModshelfSubmit

Blast Radius

Holds risky shell commands and shows what they would delete before they run

Safety and privacySide paneAbove the promptPop-up notesWrites or runs
Blast Radius running in Claude Code

Recorded on Claude Code 2.1.287 in a sandbox. Claude's replies are scripted; everything the mod draws is real.

What it does

When Claude tries to run a risky shell command, Blast Radius stops it and opens a yellow pane on the right. The pane shows the command and what it would change: for rm -rf, the files it would delete with the count and total size. Nothing runs until you choose. If you cancel, Claude is told you said no and why, so it doesn't just try again.

It holds these commands:

  • rm -r, rm -f and rm -rf: the files it would delete, with globs and ~ expanded
  • git reset --hard, git checkout -- . and git restore .: the files with uncommitted changes
  • git clean: the untracked paths it would remove
  • git push --force (also -f, --force-with-lease and +ref): the remote commits the push would drop
  • manage.py migrate, db:migrate, alembic upgrade and prisma migrate: the pending migrations

How to use it

  • Press 1 to Proceed or 2 to Cancel. You can also click a button, or Tab to it and press Enter.
  • Cancel has the focus when the pane opens, so pressing Enter refuses the command.
  • In a terminal narrower than about 144 columns, the report shows in the band above the prompt instead. There, 1 or 2 works while the input is empty.
  • If nobody answers within 10 minutes, or you interrupt the turn with Esc, the command is refused.

Good to know

  • It runs read-only commands to measure: find and du for files, git status, git diff and git clean -n for git, and the project's own status command for migrations (for example python3 manage.py showmigrations), which loads your project's code before you choose.
  • It reads the command text and doesn't parse the shell fully. $(...), bash -c "...", xargs rm, find -delete and wrappers like timeout 5 rm aren't caught.
  • After Proceed the whole command line runs as written. It's a safety net, not a sandbox: use permission rules for a hard block.
  • It only watches the Bash tool. File edits and other tools aren't held.
  • Anthropic shares it as a sample, as-is, with no support.