Cross-repo infrastructure memory for coding agents
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"blastradius-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
<p align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/harris-ahmad/blastradius-mcp/main/assets/banner-dark.svg"> <img src="https://raw.githubusercontent.com/harris-ahmad/blastradius-mcp/main/assets/banner.svg" width="620" alt="BlastRadius — cross-repo infrastructure memory for coding agents"> </picture> </p> # BlastRadius [](https://pypi.org/project/blastradius-mcp/) [](https://pypi.org/project/blastradius-mcp/) [](https://github.com/harris-ahmad/blastradius-mcp/actions/workflows/ci.yml) [](https://github.com/harris-ahmad/blastradius-mcp/blob/main/LICENSE) It remembers what every repository you open depends on, tells your agent who else is affected *before* it changes one, and watches those dependencies for vulnerabilities while nobody is asking. Not a code graph. Excellent tools already index functions, classes and imports. BlastRadius indexes the other half — Docker images, Terraform modules, GitHub Actions, Helm charts, npm and Python packages — across repository boundaries, and answers the question a single session cannot: *if I bump this, who breaks?* --- ## What it actually produces **43 advisories from OSV. 9 that apply to your pinned versions.** ``` [CRITICAL] vitest CVE-2026-47429 When Vitest UI server is listening, arbitrary file can be read and executed reaches: 3.2.4 (installed version) in: acme/checkout [HIGH ] lodash CVE-2021-23337 lodash vulnerable to Code Injection via `_.template` imports key names reaches: 4.17.21, ^4.17.21 in: acme/checkout, acme/no…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.