CI/CD Security

Don't let your workflows work against you

Because breaches aren't an option.

Your CI/CD pipelines hold the keys to your kingdom. Autonomous AI agents now execute there, processing untrusted inputs, making decisions, and acting with production credentials. Shrike finds exploitable agentic workflows before adversaries do.

$ shrike scan .
Scanning workflows...
CRITICAL: Pwn request detected
→ .github/workflows/pr-check.yml:12
→ Anyone can trigger, no approval needed
HIGH: Agentic workflow with prompt injection risk
→ .github/workflows/triage-bot.yml:8
→ Agent processes untrusted input with write permissions
Found 2 exploitable workflows
The Problem

Your pipelines are the easiest way in

GitHub Actions are easy to break

Pwn requests, script injection, over-broad tokens, and secrets reachable by outsiders keep showing up in major projects. Existing scanners report long lists of "risks," most not exploitable, so teams ignore them.

Agentic AI systems operate in your pipelines

Autonomous agents triage issues, review code, deploy infrastructure, and orchestrate releases. They process untrusted inputs and execute with privileged access. A single prompt injection can exfiltrate secrets, manipulate repositories, or compromise supply chains.

The Solution

Security that ships with your code

Exploitability, not patterns

Every finding answers: who can trigger it, what must be true first, what the attacker gets. The same pattern can be critical in one workflow and low in another.

Built for agentic security

Shrike traces data flow from untrusted inputs through agent reasoning to privileged execution, analyzing both static workflows and runtime behavior. Track every autonomous decision back to its triggering event.

Researcher-grade signal

Built by security researchers with CVEs acknowledged by Intel, Microsoft, and others. Rules come from real vulnerabilities, not theoretical patterns.

Three commands. Complete visibility.

$ shrike scan

Find exploitable workflows

Works on local checkouts or remote GitHub repos. Reports only what an attacker can actually exploit today.

$ shrike fix

Apply safe fixes

Pin actions to SHAs, add minimal permissions, move untrusted expressions. See the diff with --dry-run.

$ shrike guard

Monitor agentic behavior

Runtime observability for autonomous agents. Captures input processing, decision traces, and execution events. Detects prompt injection, unauthorized actions, and credential exposure in real-time.

Open Core

Free forever. Paid tier for teams.

Open Source

Anything one developer needs to secure one repo is free and open source. Apache 2.0 licensed.

  • Scan workflows for agentic vulnerabilities
  • Automated security fixes with --dry-run
  • Runtime agent behavior monitoring
  • GitHub Action for continuous scanning
Get Started

Start securing your pipelines today

# macOS / Linux
$ brew install chelate-dev/tap/shrike

# Or download directly
$ curl -L https://github.com/ChelateSec/shrike/releases/latest/download/shrike-linux-amd64 -o shrike

# Scan your repo
$ shrike scan .
View Documentation Read the Blog