Bolt
A security workspace that shows its work.
Bring the case and the evidence. Lookups run inside your scope, the result is graded, and the reasoning stays attached to it — in the workspace or your terminal.
01
How a case runs
One prompt in, arranged output out. Defensive analysis or authorized testing — the shape of the answer follows what you asked.
- 01
Open a case
Name the incident, the asset, and the severity. Attach the log, trace, or file that started it.
- 02
Run the work
Lookups and analysis run inside your scope. One prompt chains the steps; nothing is inferred the evidence does not support.
- 03
Read the verdict
A scoped result with the evidence attached and the reasoning written out, so a reviewer can check it.
02
What actually runs
Passive lookups and read-only checks. Active scripts are written for you to run on your own machines.
| Check | What it does |
|---|---|
| Dependencies | Advisories from OSV.dev, matched against the resolved lockfile. |
| Code | Pattern and regex rules over the code that ships. |
| Secrets | Entropy and pattern detection, with the match shown in place. |
| Infrastructure | Dockerfile, Terraform, Kubernetes, and GitHub Actions definitions. |
| Containers | OCI manifest and configuration. Layers are never pulled. |
03
How it is charged
One balance for workspace and terminal. Every run bills the same way.
Top up, then spend
Secure checkout handles payment. The remaining balance sits next to the work consuming it, and bolt balance shows it from the terminal.
What costs tokens
- Case size.
- How far the analysis reads to grade it.
- How many times you revise and re-run.
04
Use it from your terminal
Same loop as the workspace, from any shell — including the VS Code integrated terminal. Sign in, check health, then run.
$ npm install -g bolt-sec $ bolt login $ bolt doctor $ bolt run "get admin endpoints" --target tesla.com --format json $ bolt export <session> --format sarif --output findings.sarif
One prompt in, arranged output out.
- Subdomain and HTTP checks chain themselves in one run.
- Builds save to disk for your own Kali/WSL.
- JSON output and SARIF export ride the CI path.
- Account first, tokens second — runs bill your balance.
05
Terminal upgrades that survive review
Health checks, machine-readable output, and an undo net — so terminal work holds up in a pipeline and in an audit.
| Capability | Command |
|---|---|
| Pre-flight checks | bolt doctor — node, auth, backend, WSL, clipboard. |
| CI-ready output | bolt run "..." --format json --output out.json |
| Token budget guard | bolt run "..." --budget 8000 refuses before spending. |
| Session export | bolt export <id> --format md|json|sarif |
| Undo net | bolt undo src/auth.ts restores the last agent edit. |
| Stop any run | Esc cancels and saves the session; empty balance stops with the top-up link. |
| Shell completions | bolt completion bash|zsh|fish|powershell |
| Directory listing | list tool — the agent sees folders without shelling out. |
| Per-command help | bolt help run|build|export|doctor |
In the interactive session: /retry re-runs the last prompt, /export saves the session, /undo restores a file, /doctor checks health.

