Detector libraryFile blast radius

File blast radius

One small task. Thirty files changed.

See when an agent task reaches more files than expected.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

You asked for a small fix. The agent starts touching files across the project. A broad refactor can be correct, but it deserves a different level of attention from a one line change.

The risk is easy to miss when file operations appear one at a time. Each edit looks small in isolation. Together, they can affect a much larger part of the project than the original task suggested.

What ClawMetry detects

ClawMetry examines captured tool arguments for the scope of file changes and destructive command patterns. A wide edit can raise a file blast radius warning. Recognized recursive deletion aimed at a root location can raise a critical finding.

The difference that changes the finding

Triggering example

30 distinct file writes

Warning finding

Quiet comparison

4 distinct file writes

No finding for this detector.

In the checked comparison, writes to thirty distinct files raise a warning. Writes to four files stay quiet. The wide-edit threshold can vary with the runtime and its baseline. The finding gives you a count and bounded evidence to focus the review.

Inspect the detector result
{
  "kind": "file_blast_radius",
  "severity": "warning",
  "evidence": {
    "distinct_files": 30,
    "write_calls": 30,
    "threshold": 25,
    "threshold_source": "static",
    "baseline": null,
    "outside_workspace": 0,
    "destructive": [],
    "samples": [
      "example/f0.py",
      "example/f1.py",
      "example/f2.py"
    ],
    "observed": "tool_arguments"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Compare the affected scope with the request. Inspect the actual diff, especially generated changes and deletions. Confirm that tests cover the files involved before accepting the result. The point is to catch an unexpectedly broad change while you still have context.

  1. Compare scope with task
  2. Review the actual diff
  3. Check tests and deletions

What this signal establishes

This reads tool arguments, not filesystem syscalls. It reports after the action and does not prove every named change succeeded.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.