Install latest/stable of Grackle
Ubuntu 16.04 or later?
Make sure snap support is enabled in your Desktop store.
You are about to open
Do you wish to proceed?
Thank you for your report. Information you provided will help us investigate further.
There was an error while sending your report. Please try again later.
Generate an embeddable card to be shared on external websites.
grackle is a static scanner that detects fork-triggerable AI coding agents with repository write access in GitHub Actions and GitLab CI workflows.
When an AI coding agent runs on untrusted fork input in a job that can write to the repository and nothing checks who triggered it, prompt injection becomes remote code execution and repository takeover under the CI token. grackle finds that exact composition statically, before it merges. It proves fork reachability, author and merge gates, and write capability, and reports only the compositions that are actually exploitable.
Findings carry a severity, a confidence, the offending workflow block, a dynamic secure-fix write-up, and control-framework references (CWE, OWASP, MITRE ATT&CK and ATLAS, NIST, CIS). Outputs SARIF, GitLab SAST, CycloneDX SBOM, JUnit, JSON, HTML, Markdown, YAML, CSV, and XML.
Releases are Sigstore-signed with SLSA Build Level 3 provenance.
Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the installing snapd documentation.