> **Catch an MCP server that touches files it said it wouldn't — and block the merge in CI.** Statically extract what a third-party MCP server can actually reach (files, network, subprocess, env) and compare against declared boundaries when a manifest is present. ```bash pipx run mcp-blast-radius # MCP server