The Trending Math Is… Not Great
Let me start with the uncomfortable numbers. The blast-radius skill by Aqua-123 has seven stars on SkillsMP. Zero stars gained in the last seven days. If you're evaluating whether to install this, the market is telling you something. But seven people found it valuable enough to click the star, and those seven aren't necessarily wrong — sometimes a niche tool is genuinely useful for exactly the people who need it, even if nobody else cares.
So let me tell you what I actually think after reading through the SKILL.md, the repo README, and the broader pstack-for-codex ecosystem.
What This Skill Actually Does
blast-radius is a review skill. You give it a code change — a diff, a PR, a set of symbols — and it forces you to answer one question before you ship: what could this break somewhere else?
But here's the part that makes it different from every other "review this diff" prompt you've ever written: it doesn't accept your reasoning. Not at face value. The skill explicitly calls out that "a blast-radius writeup that sounds right is worthless. It reads as convincing whether or not it's true, and that is the trap you are walking into."
It wants you to find the one fact that makes a change safe, then prove it by running code. Not by citing a comment. Not by pointing at a line. By running the actual code and showing it works.
The Problem It Solves
Here's a pattern I've lived in for years: someone ships a small, innocent-looking change — "we're just clearing expired cache entries" — and three weeks later something downstream breaks because that cache clearing had a side effect nobody modeled. The diff looked safe. The mental model was wrong. The review was thorough on paper.
blast-radius targets exactly this failure mode. It's built on the insight that grep-based dependency analysis — "who calls this function?" — misses the real blast radius. The real danger lives in JSON shapes, DB columns, wire formats, feature flags, timing semantics (microtasks vs. macrotasks), and the library version you pinned last Tuesday.
The skill's methodology is a six-step process that escalates from "you said so" (worthless) to "you ran it" (actually useful). Step 4 is the line in the sand: if you can't prove a safety fact with a script or test that fails loud when you're wrong, you admit it's unproven. No hand-waving. No rounding up.
What I Actually Liked
1. The "one fact" heuristic. Most changes that look scary are safe because of a single fact. Finding that fact collapses most of the anxiety. The skill forces you to identify it explicitly rather than drowning in a list of maybes. This is genuinely good engineering thinking.
2. The proof hierarchy. The five-step confidence scale — from "you said so" to "you reproduced it in the running app" — is a real framework. It maps cleanly to how I actually think about risk in production systems. The skill doesn't let you stop at step 2 and call it a day.
3. "Look where grep stops." This is the most practical instruction in the whole document. Grep finds callers. It doesn't find the JSON field an API returns, the DB column that feeds it, the feature flag that gates it, or the other language reading the same bytes. The skill names these explicitly. That's the kind of thing experienced engineers think about intuitively but rarely articulate.
4. The companion ecosystem. blast-radius is one of 48 skills in the pstack-for-codex suite, with $how, $why, $arena, $unslop, and $interrogate all designed to work together. If you're already in that ecosystem, blast-radius slots in naturally.
Who Should Install This (And Who Shouldn't)
Install this if: - You work in a codebase where small changes have outsized blast radius (distributed systems, shared libraries, infrastructure code). - You've been burned by a "harmless" change before and want a structured way to prevent it. - You're already using the pstack-for-codex plugin ecosystem and want the full workflow. - You're the kind of reviewer who instinctively reaches for "I think it's fine" and want someone to push you to actually prove it.
Don't install this if:
- You're a solo developer on a small project. The overhead of writing a proof script for every PR is not worth it.
- You're looking for a Claude Code skill. This is a Codex plugin. It installs via codex plugin marketplace add, not ~/.claude/skills/. That's a real distinction.
- You want a quick diff review. This skill is methodical and deliberate. It will take longer than a skim.
- You're turned off by the 7-star, zero-growth signal. That signal exists for a reason — it might be a niche tool in a niche ecosystem.
Honest Concerns
It's Codex-only. The entire pstack-for-codex suite is built for the Codex CLI. The installation instructions are codex plugin marketplace add Aqua-123/pstack-for-codex. If you live in Claude Code, this isn't going to work without significant adaptation. The task instructions mention ~/.claude/skills/, but the actual skill is not structured for that path.
The ecosystem lock-in is real. blast-radius references ../poteto-mode/references/codex-agent-runtime.md, uses $poteto-mode as an entry point, and expects companion skills. Installing just blast-radius in isolation means you're missing half the workflow. You're either all-in on pstack or you're fighting the tool.
The proof requirement is expensive. Writing a script that "imports the same library the app ships and calls the exact function you're worried about" is genuinely valuable, but it's also real engineering work. For a two-line typo fix, this is overkill. For a refactor that touches a shared cache layer, it might save your job.
The star count and momentum are telling. Seven stars, zero growth in a week, "trend status: unknown." This isn't a widely adopted tool. It could be because it's niche by design, or because the Codex-specific positioning limits its audience. Either way, you're adopting something with very little community validation.
The Verdict
blast-radius is a genuinely well-designed skill with a sharp methodology. The "prove the one fact it's safe because of" approach is the most honest review framework I've seen in any skill marketplace. It's not asking you to be smarter — it's asking you to be more rigorous.
But it's a specialist tool in a specialist ecosystem. If you're already running Codex with pstack-for-codex, install it and use it. If you're evaluating it cold, I'd say: try it on one real PR that scared you, see if the methodology changes how you think about risk, and decide from there.
The skill itself is good. The question is whether the ecosystem around it is worth the lock-in.
SkillsMP: skillsmp.com/creators/aqua-123/pstack-for-codex/skills-blast-radius GitHub: github.com/Aqua-123/pstack-for-codex/tree/main/skills/blast-radius