Because breaches aren't an option.
Your CI/CD pipelines hold the keys to your kingdom. AI agents now run there too, reading untrusted text and acting with real tokens. Shrike finds exploitable workflows before attackers do.
Pwn requests, script injection, over-broad tokens, and secrets reachable by outsiders keep showing up in major projects. Existing scanners report long lists of "risks," most not exploitable, so teams ignore them.
They triage issues, review PRs, and fix bugs. They read untrusted text and act with real tokens. One hidden instruction can make an agent leak secrets, push to main, or publish a package.
Every finding answers: who can trigger it, what must be true first, what the attacker gets. The same pattern can be critical in one workflow and low in another.
Shrike traces untrusted text → agent → privileged action, both statically and at runtime. It links every agent action to the input that caused it.
Rules come from real vulnerabilities and bug bounty experience. Few, precise findings beat many noisy ones.
Works on local checkouts or remote GitHub repos. Reports only what an attacker can actually exploit today.
Pin actions to SHAs, add minimal permissions, move untrusted expressions. See the diff with --dry-run.
Audit-only runtime monitor. Records what agents read and did, flags hidden instructions and secret exposure.
Anything one developer needs to secure one repo is free and open source. Apache 2.0 licensed.
Org-wide enforcement, runtime blocking, and compliance. Control every repo without opt-in.
# macOS / Linux
$ brew install chelate-dev/tap/shrike
# Or download directly
$ curl -L https://github.com/ChelateSec/shrike/releases/latest/download/shrike-linux-amd64 -o shrike
# Scan your repo
$ shrike scan .