Because breaches aren't an option.
Your CI/CD pipelines hold the keys to your kingdom. Autonomous AI agents now execute there, processing untrusted inputs, making decisions, and acting with production credentials. Shrike finds exploitable agentic workflows before adversaries do.
Pwn requests, script injection, over-broad tokens, and secrets reachable by outsiders keep showing up in major projects. Existing scanners report long lists of "risks," most not exploitable, so teams ignore them.
Autonomous agents triage issues, review code, deploy infrastructure, and orchestrate releases. They process untrusted inputs and execute with privileged access. A single prompt injection can exfiltrate secrets, manipulate repositories, or compromise supply chains.
Every finding answers: who can trigger it, what must be true first, what the attacker gets. The same pattern can be critical in one workflow and low in another.
Shrike traces data flow from untrusted inputs through agent reasoning to privileged execution, analyzing both static workflows and runtime behavior. Track every autonomous decision back to its triggering event.
Built by security researchers with CVEs acknowledged by Intel, Microsoft, and others. Rules come from real vulnerabilities, not theoretical patterns.
Works on local checkouts or remote GitHub repos. Reports only what an attacker can actually exploit today.
Pin actions to SHAs, add minimal permissions, move untrusted expressions. See the diff with --dry-run.
Runtime observability for autonomous agents. Captures input processing, decision traces, and execution events. Detects prompt injection, unauthorized actions, and credential exposure in real-time.
Anything one developer needs to secure one repo is free and open source. Apache 2.0 licensed.
Runtime blocking, org-wide policies, and centralized visibility for teams that need more control.
# macOS / Linux
$ brew install chelate-dev/tap/shrike
# Or download directly
$ curl -L https://github.com/ChelateSec/shrike/releases/latest/download/shrike-linux-amd64 -o shrike
# Scan your repo
$ shrike scan .