Back to skill

Security audit

AllToken

Security checks for vulnerabilities and agentic risk

Overview

The visible artifacts look like a normal AllToken bootstrap recipe, but using it will create project files, install packages, use an AllToken API key, and send requests to AllToken.

This appears safe to install as an instruction-only bootstrap skill if you intend to build an AllToken project. Before using it, choose the target directory carefully, keep ALLTOKEN_API_KEY out of source control, review npm dependencies, and remember that smoke tests and generated apps may spend credits and send prompts to AllToken.

Static analysis

No suspicious patterns detected.