Install latest/stable of Grackle

Ubuntu 16.04 or later?

Make sure snap support is enabled in your Desktop store.


Install using the command line

sudo snap install grackle

Don't have snapd? Get set up for snaps.

Channel Version Published

Details for Grackle

Package name

  • grackle

License

  • Apache-2.0

Last updated

  • 23 July 2026 - latest/stable

Websites


Contact


Donations


Source code


Report a bug


Report a Snap Store violation

Share this snap

Generate an embeddable card to be shared on external websites.

Scanner for fork-triggerable CI coding agents with repo write access

grackle is a static scanner that detects fork-triggerable AI coding agents with repository write access in GitHub Actions and GitLab CI workflows.

When an AI coding agent runs on untrusted fork input in a job that can write to the repository and nothing checks who triggered it, prompt injection becomes remote code execution and repository takeover under the CI token. grackle finds that exact composition statically, before it merges. It proves fork reachability, author and merge gates, and write capability, and reports only the compositions that are actually exploitable.

Findings carry a severity, a confidence, the offending workflow block, a dynamic secure-fix write-up, and control-framework references (CWE, OWASP, MITRE ATT&CK and ATLAS, NIST, CIS). Outputs SARIF, GitLab SAST, CycloneDX SBOM, JUnit, JSON, HTML, Markdown, YAML, CSV, and XML.

Releases are Sigstore-signed with SLSA Build Level 3 provenance.


Install Grackle on your Linux distribution

Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the installing snapd documentation.


Where people are using Grackle