CI/CD Security

Don't let your workflows work against you

Because breaches aren't an option.

Your CI/CD pipelines hold the keys to your kingdom. AI agents now run there too, reading untrusted text and acting with real tokens. Shrike finds exploitable workflows before attackers do.

$ shrike scan .
Scanning workflows...
CRITICAL: Pwn request detected
→ .github/workflows/pr-check.yml:12
→ Anyone can trigger, no approval needed
HIGH: AI agent with untrusted input
→ .github/workflows/triage-bot.yml:8
→ Reads issue body, has GITHUB_TOKEN write access
Found 2 exploitable workflows
The Problem

Your pipelines are the easiest way in

GitHub Actions are easy to break

Pwn requests, script injection, over-broad tokens, and secrets reachable by outsiders keep showing up in major projects. Existing scanners report long lists of "risks," most not exploitable, so teams ignore them.

AI agents run inside CI now

They triage issues, review PRs, and fix bugs. They read untrusted text and act with real tokens. One hidden instruction can make an agent leak secrets, push to main, or publish a package.

The Solution

Security that ships with your code

Exploitability, not patterns

Every finding answers: who can trigger it, what must be true first, what the attacker gets. The same pattern can be critical in one workflow and low in another.

Built for AI agents

Shrike traces untrusted text → agent → privileged action, both statically and at runtime. It links every agent action to the input that caused it.

Researcher-grade signal

Rules come from real vulnerabilities and bug bounty experience. Few, precise findings beat many noisy ones.

Three commands. Complete visibility.

$ shrike scan

Find exploitable workflows

Works on local checkouts or remote GitHub repos. Reports only what an attacker can actually exploit today.

$ shrike fix

Apply safe fixes

Pin actions to SHAs, add minimal permissions, move untrusted expressions. See the diff with --dry-run.

$ shrike guard

Monitor AI agents

Audit-only runtime monitor. Records what agents read and did, flags hidden instructions and secret exposure.

Open Core

Free forever. Enterprise when you need it.

Open Source

Anything one developer needs to secure one repo is free and open source. Apache 2.0 licensed.

  • Scan local and remote repos
  • Automated fixes with --dry-run
  • Audit-only runtime monitoring
  • GitHub Action for CI scanning
Get Started

Start securing your pipelines today

# macOS / Linux
$ brew install chelate-dev/tap/shrike

# Or download directly
$ curl -L https://github.com/ChelateSec/shrike/releases/latest/download/shrike-linux-amd64 -o shrike

# Scan your repo
$ shrike scan .
View Documentation Read the Blog