bolt — security grade SAFE, quality 58/100

Security audit verdict: SAFE · quality 58/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by puppetlabs · Agent Tool · ★ 556

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is bolt safe to install? View the security audit →

About bolt

Bolt is an open source orchestration tool that automates the manual work it takes to maintain your infrastructure. Use Bolt to automate tasks that you perform on an as-needed basis or as part of a greater orchestration workflow. For example, you can use Bolt to patch and update systems, troubleshoot servers, deploy applications, or stop and restart services. Bolt can be installed on your local workstation and connects directly to remote targets with SSH or WinRM, so you are not required to install any agent software. Bring order to the chaos with orchestration Run simple plans to rid yourself of the headaches of orchestrating complex workflows. Create and shar

boltdevopsorchestrationpuppetsshwinrm

Quick Facts

Stars556
Forks225
LanguageRuby
CategoryAgent Tool
LicenseApache-2.0
Quality Score58.4195622190567/100
Open Issues100
Last Updated2026-08-21
Created2017-08-11
Platformsruby
Est. Tokens~14k

Compatible Skills

These tools work well together with bolt for enhanced workflows:

  • mcp-ssh-manager — semantic(0.33)+complementary+rare_topics+similar_pop (46%)

bolt alternative? Top 6 similar tools

Looking for a bolt alternative? If you're comparing bolt with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-ssh-manager by bvisible · ⭐ 467

    MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups,

  • homebutler by Higangssh · ⭐ 290

    🏠 Tells you what changed on your server — only what's worth telling. Single Go binary, no database, nothing r

  • claude-code-plugins-plus-skills by jeremylongshore · ⭐ 2.7k

    471 plugins, 3,069 skills, 347 agents for Claude Code. Open-source marketplace at tonsofskills.com with the cc

  • commands by wshobson · ⭐ 2.6k

    A collection of production-ready slash commands for Claude Code

  • CodeMachine-CLI by moazbuilds · ⭐ 2.5k

    CodeMachine is an open-source tool that orchestrates AI coding agents into repeatable, long-running workflows.

  • terraform-skill by antonbabenko · ⭐ 2.4k

    Terraform & OpenTofu Skill for AI Agents - testing, modules, CI/CD, and production patterns

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Ruby Agent Tools

Frequently Asked Questions

What is bolt?

bolt is Bolt is an open source orchestration tool that automates the manual work it takes to maintain your infrastructure on an as-needed basis or as part of a greater orchestration workflow. It can be instal. It is categorized as a Agent Tool with 556 GitHub stars.

What programming language is bolt written in?

bolt is primarily written in Ruby. It covers topics such as bolt, devops, orchestration.

How do I install or use bolt?

You can find installation instructions and usage details in the bolt GitHub repository at github.com/puppetlabs/bolt. The project has 556 stars and 225 forks, indicating an active community.

What license does bolt use?

bolt is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to bolt?

The top alternatives to bolt on Agent Skills Hub include mcp-ssh-manager, homebutler, claude-code-plugins-plus-skills. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools