Version0.1.3
Revision3
Size1.9 MB
LicenseApache-2.0
Confinementstrict
Basecore24

Scanner for fork-triggerable CI coding agents with repo write access


grackle is a static scanner that detects fork-triggerable AI coding agents
with repository write access in GitHub Actions and GitLab CI workflows.

When an AI coding agent runs on untrusted fork input in a job that can write
to the repository and nothing checks who triggered it, prompt injection
becomes remote code execution and repository takeover under the CI token.
grackle finds that exact composition statically, before it merges. It proves
fork reachability, author and merge gates, and write capability, and reports
only the compositions that are actually exploitable.

Findings carry a severity, a confidence, the offending workflow block, a
dynamic secure-fix write-up, and control-framework references (CWE, OWASP,
MITRE ATT&CK and ATLAS, NIST, CIS). Outputs SARIF, GitLab SAST, CycloneDX
SBOM, JUnit, JSON, HTML, Markdown, YAML, CSV, and XML.

Releases are Sigstore-signed with SLSA Build Level 3 provenance.

Update History

0.1.1 (2)0.1.3 (3)
23 Jul 2026, 15:15 UTC
0.1.1 (2)
21 Jul 2026, 21:15 UTC

Published21 Jul 2026, 20:33 UTC

Last updated23 Jul 2026, 15:03 UTC

First seen21 Jul 2026, 21:15 UTC