---
title: Install Grackle on Linux | Snap Store
description: Get the latest version of Grackle for Linux - Scanner for fork-triggerable
  CI coding agents with repo write access
url: https://snapcraft.io/grackle
---

# Grackle

[Chris Peoples (cpeoples)](https://snapcraft.io/publisher/cpeoples "View all snaps from Chris Peoples (cpeoples)")

* [Chris Peoples (cpeoples)](https://snapcraft.io/publisher/cpeoples "View all snaps from Chris Peoples (cpeoples)")
* [Development](https://snapcraft.io/search?categories=development)
* [Security](https://snapcraft.io/search?categories=security)

latest/stable 0.1.5

Install latest/stable of Grackle

---

**Install using the command line**

```
sudo snap install grackle
```

Don't have snapd? [Get set up for snaps](https://snapcraft.io/docs/installing-snapd).

---

### Package name

* grackle

---

### License

* Apache-2.0

---

### Last updated

* 4 August 2026 - latest/stable

---

### Websites

* [cpeoples.github.io](https://cpeoples.github.io/grackle/ "https://cpeoples.github.io/grackle/")

---

### Contact

* [github.com/cpeoples/grackle/issues](https://github.com/cpeoples/grackle/issues "https://github.com/cpeoples/grackle/issues")

---

### Donations

* [github.com/sponsors/cpeoples](https://github.com/sponsors/cpeoples "https://github.com/sponsors/cpeoples")

---

### Source code

* [github.com/cpeoples/grackle](https://github.com/cpeoples/grackle "https://github.com/cpeoples/grackle")

---

### Report a bug

* [github.com/cpeoples/grackle/issues](https://github.com/cpeoples/grackle/issues "https://github.com/cpeoples/grackle/issues")

---

##### Report a Snap Store violation

* [Report this Snap](https://snapcraft.io/grackle#report-snap-modal)

---

* [Description](https://snapcraft.io/grackle#tab-description)
* [Security](https://snapcraft.io/grackle#tab-security)

#### Scanner for fork-triggerable CI coding agents with repo write access

grackle is a static scanner that detects fork-triggerable AI coding agents
with repository write access in GitHub Actions and GitLab CI workflows.

When an AI coding agent runs on untrusted fork input in a job that can write
to the repository and nothing checks who triggered it, prompt injection
becomes remote code execution and repository takeover under the CI token.
grackle finds that exact composition statically, before it merges. It proves
fork reachability, author and merge gates, and write capability, and reports
only the compositions that are actually exploitable.

Findings carry a severity, a confidence, the offending workflow block, a
dynamic secure-fix write-up, and control-framework references (CWE, OWASP,
MITRE ATT&CK and ATLAS, NIST, CIS). Outputs SARIF, GitLab SAST, CycloneDX
SBOM, JUnit, JSON, HTML, Markdown, YAML, CSV, and XML.

Releases are Sigstore-signed with SLSA Build Level 3 provenance.

---

## Install Grackle on your Linux distribution

Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the [installing snapd documentation](https://snapcraft.io/docs/installing-snapd).

[### Arch Linux](https://snapcraft.io/install/grackle/arch)

[### CentOS](https://snapcraft.io/install/grackle/centos)

[### Debian](https://snapcraft.io/install/grackle/debian)

[### elementary OS](https://snapcraft.io/install/grackle/elementary)

[### Fedora](https://snapcraft.io/install/grackle/fedora)

[### KDE Neon](https://snapcraft.io/install/grackle/kde-neon)

[### Kubuntu](https://snapcraft.io/install/grackle/kubuntu)

[### Manjaro](https://snapcraft.io/install/grackle/manjaro)

[### Pop!\_OS](https://snapcraft.io/install/grackle/pop)

[### openSUSE](https://snapcraft.io/install/grackle/opensuse)

[### Red Hat Enterprise Linux](https://snapcraft.io/install/grackle/rhel)

[### Ubuntu](https://snapcraft.io/install/grackle/ubuntu)
