Bolt
A security workspace that shows its work.
Bring the case and the evidence. Lookups run inside your scope, the result is graded, and the reasoning stays attached to it — in the workspace or your terminal.
01
How a case runs
One prompt in, arranged output out. Defensive analysis or authorized testing — the shape of the answer follows what you asked.
- 01
Open a case
Name the incident, the asset, and the severity. Attach the log, trace, or file that started it.
- 02
Run the work
Lookups and analysis run inside your scope. One prompt chains the steps; nothing is inferred the evidence does not support.
- 03
Read the verdict
A scoped result with the evidence attached and the reasoning written out, so a reviewer can check it.
02
What actually runs
Passive lookups and read-only checks. Active scripts are written for you to run on your own machines.
| Check | What it does |
|---|---|
| Dependencies | Advisories from OSV.dev, matched against the resolved lockfile. |
| Code | Pattern and regex rules over the code that ships. |
| Secrets | Entropy and pattern detection, with the match shown in place. |
| Infrastructure | Dockerfile, Terraform, Kubernetes, and GitHub Actions definitions. |
| Containers | OCI manifest and configuration. Layers are never pulled. |
03
How it is charged
One balance for workspace and terminal. Every run bills the same way.
Top up, then spend
Secure checkout handles payment. The remaining balance sits next to the work consuming it, and bolt balance shows it from the terminal.
What costs tokens
- Case size.
- How far the analysis reads to grade it.
- How many times you revise and re-run.
04
Use it from your terminal
Same loop as the workspace, from any shell — including the VS Code integrated terminal. Sign in, top up, then run.
$ npm install -g bolt-sec $ bolt login $ bolt run "get admin endpoints" --target tesla.com $ bolt build "nmap NSE for admin logins" --out ./bolt-out
One prompt in, arranged output out.
- Subdomain and HTTP checks chain themselves in one run.
- Builds save to disk for your own Kali/WSL.
- Account first, tokens second — runs bill your balance.

