Bolt

A security workspace that shows its work.

Bring the case and the evidence. Lookups run inside your scope, the result is graded, and the reasoning stays attached to it — in the workspace or your terminal.

01

How a case runs

One prompt in, arranged output out. Defensive analysis or authorized testing — the shape of the answer follows what you asked.

  1. 01

    Open a case

    Name the incident, the asset, and the severity. Attach the log, trace, or file that started it.

  2. 02

    Run the work

    Lookups and analysis run inside your scope. One prompt chains the steps; nothing is inferred the evidence does not support.

  3. 03

    Read the verdict

    A scoped result with the evidence attached and the reasoning written out, so a reviewer can check it.

02

What actually runs

Passive lookups and read-only checks. Active scripts are written for you to run on your own machines.

CheckWhat it does
DependenciesAdvisories from OSV.dev, matched against the resolved lockfile.
CodePattern and regex rules over the code that ships.
SecretsEntropy and pattern detection, with the match shown in place.
InfrastructureDockerfile, Terraform, Kubernetes, and GitHub Actions definitions.
ContainersOCI manifest and configuration. Layers are never pulled.

03

How it is charged

One balance for workspace and terminal. Every run bills the same way.

Top up, then spend

Secure checkout handles payment. The remaining balance sits next to the work consuming it, and bolt balance shows it from the terminal.

What costs tokens

  • Case size.
  • How far the analysis reads to grade it.
  • How many times you revise and re-run.
See packages

04

Use it from your terminal

Same loop as the workspace, from any shell — including the VS Code integrated terminal. Sign in, check health, then run.

terminal — npm i -g bolt-sec
$ npm install -g bolt-sec
$ bolt login
$ bolt doctor
$ bolt run "get admin endpoints" --target tesla.com --format json
$ bolt export <session> --format sarif --output findings.sarif

One prompt in, arranged output out.

  • Subdomain and HTTP checks chain themselves in one run.
  • Builds save to disk for your own Kali/WSL.
  • JSON output and SARIF export ride the CI path.
  • Account first, tokens second — runs bill your balance.

05

Terminal upgrades that survive review

Health checks, machine-readable output, and an undo net — so terminal work holds up in a pipeline and in an audit.

CapabilityCommand
Pre-flight checksbolt doctor — node, auth, backend, WSL, clipboard.
CI-ready outputbolt run "..." --format json --output out.json
Token budget guardbolt run "..." --budget 8000 refuses before spending.
Session exportbolt export <id> --format md|json|sarif
Undo netbolt undo src/auth.ts restores the last agent edit.
Stop any runEsc cancels and saves the session; empty balance stops with the top-up link.
Shell completionsbolt completion bash|zsh|fish|powershell
Directory listinglist tool — the agent sees folders without shelling out.
Per-command helpbolt help run|build|export|doctor

In the interactive session: /retry re-runs the last prompt, /export saves the session, /undo restores a file, /doctor checks health.