Security audit
AllToken
Security checks for vulnerabilities and agentic risk
Overview
The visible artifacts look like a normal AllToken bootstrap recipe, but using it will create project files, install packages, use an AllToken API key, and send requests to AllToken.
This appears safe to install as an instruction-only bootstrap skill if you intend to build an AllToken project. Before using it, choose the target directory carefully, keep ALLTOKEN_API_KEY out of source control, review npm dependencies, and remember that smoke tests and generated apps may spend credits and send prompts to AllToken.
Static analysis
No suspicious patterns detected.
