shrike

mcp
Guvenlik Denetimi
Basarisiz
Health Gecti
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Community trust — 19 GitHub stars
Code Basarisiz
  • exec() — Shell command execution in apps/desktop/e2e/agent-surface.test.ts
  • process.env — Environment variable access in apps/desktop/e2e/agent-surface.test.ts
  • network request — Outbound network request in apps/desktop/e2e/agent-surface.test.ts
  • process.env — Environment variable access in apps/desktop/e2e/agent.test.ts
Permissions Gecti
  • Permissions — No dangerous permissions requested

Bu listing icin henuz AI raporu yok.

SUMMARY

The open source debugger for people who build web apps with AI. Click the thing that breaks; see the whole trip to the exact line; your agent fixes it after you say OK.

README.md

Shrike: your app, recorded. Your agent, with eyes. A dot-drawn shrike next to a click that travels from the page to the server and breaks on todos.controller.ts line 18.

Latest release macOS on Apple Silicon CI status MIT license GitHub stars Ships an MCP server

The open source debugger for people who build web apps with AI.

Run your app inside Shrike and click the thing that breaks.
Shrike records the whole trip, from the button to the database, and your own coding agent
finds the line, fixes it after you say OK, and clicks again to prove it works.

Works with Node backends (Express, Next.js, NestJS, Hono, Remix), Python 3.12+ backends (FastAPI, Flask, Django) and Vite or Next frontends. Any other backend that speaks OpenTelemetry (.NET, Go, Java, older Python) gets basic tracing.

Download for Mac · Quick start · Walkthrough · How it works · Docs

Clicking Add Todo in a broken app: Shrike draws the trip from the page to the database and lands on line 18

Watch the 40 second launch video
Watch the 40 second launch video on YouTube

Why Shrike

You built an app with Cursor, Claude Code, Lovable or Bolt. It works until it doesn't. A button does nothing, so you paste the error into a chat and the model guesses from the code.

Without Shrike With Shrike
  • You copy logs from three terminals
  • You guess which request it was
  • The model reads code and guesses
  • "Try this" until something sticks
  • One click is recorded end to end
  • The broken step turns red, on its line
  • The agent reads what really ran, with the bad value
  • It shows a diff, you approve, it re-runs the click

Shrike is for you if

  • You build with AI and can run npm run dev, but stack traces still feel like guesswork
  • You want to see what your code did when you clicked, not read 40 files to find out
  • You want your agent to fix things with proof, and never touch a file without asking

What happens when you click

1. Click. The trip draws itself and stops where it broke.
Every click becomes a trip across lanes: you, page, server, database. The step that failed turns red, and Shrike dives into the code with the real value inline, like userId: undefined on line 18.

The Thread: a click on Add Todo travels to the server and snaps on todos.controller.ts line 18 with userId undefined shown inline

2. Press E. See the whole file, and every file the click touched.
The Files view opens on the line that ran, next to a tree of every file in the trip. Hot rows ran, red rows broke. The strip at the bottom is the call path you can scrub.

Files view: the failing line in totals.ts with its value, the project tree with the files that ran lit up, and the call path strip

3. Ask in plain words. Your agent says "Found it".
Type "when I click Add Todo nothing shows up". The agent walks the recorded trip, pins the cause on a line, and says why in one sentence. You see which playbook it used.

The agent's Found it card on todos.controller.ts line 18: createTodo reads req.body.user, but the page sends userId

4. Approve the diff. Then ship it.
The fix lands only after your click, and Shrike replays the same click to show it passes. Commit, open a pull request, and read CI failures and review comments in the same window.

Pull request panel: one failing check explained in plain words with Fix it, Explain and Learn from this buttons, and the review conversation below

Features

Any stack, any size

A click in Bazaar, the big sample app, crosses 8 services, 3 Postgres databases, an SQLite outbox, 3 LRU caches, a queue, Stripe and an email provider. Shrike finds the lanes by itself and still stops on the one bad line.

Postgres, MySQL, SQLite, MongoDB, Redis, DynamoDB, Firestore, Supabase. Tested projects →

A Place order click across many lanes (queue, LRU caches, Postgres, SQLite, Stripe, email) snapping at totals.ts line 25

API client

A Bruno-style request editor. Routes are found for you, collections are plain files in your repo, and you can import from Bruno, OpenAPI and cURL. Every request you send becomes a trip, so you see what the server did with it.

API client sending GET /api/todos with the JSON response

Workspaces and worktrees

Try a fix in a git worktree copy with its own ports and its own agent. Race two fixes side by side and keep the one that passes. Many projects, one rail.

Docs →

Workspaces rail with main, a feature branch, a fix worktree and a pull request, each running on its own port

The Thread
Each click as a trip across lanes, with timings, values and the line of code for every step.

Files view
The real files, open on the line that ran, with the values that passed through it.

Agent fix, with approvals
Found it, a diff, your click, a replay. Agents can't write files on their own.

Skills that evolve
Playbooks like "Bad value" and "N+1 hunter". When a run teaches something, the skill updates after the fix is verified, with one-click Undo.

PR and CI
Commit, push, open a PR, read checks and reviews, turn failures into lessons. Anything that leaves your Mac asks first.

MCP hub
Shrike's tools are an MCP server: paste one line and the Claude Code in your terminal reads the same recordings, and still changes code only after you click Apply. Add your own servers too.

Voice
Hold Option+Space and say "show the logs" or "next step". Speech runs on your Mac. English, Hindi and Hinglish tested.

Look inside your data
Click a database or cache lane to see its tables or keys, and what this click changed.

Local and private
No account, no telemetry. Secrets are stripped before anything is stored, shown or sent.

Works today with Node servers (Express, Next.js, NestJS, Hono, Remix), Python 3.12+ servers (FastAPI, Flask, Django) and Vite or Next frontends. On Python, Shrike records every call into your own code with its arguments, what it returned and its file and line, nested under the request that caused it, plus its sqlite3 queries, with no change to your code (packages/python-agent). Any backend that speaks OpenTelemetry (.NET, Go, Java, Python before 3.12) works with basic tracing: its requests, queries and outside calls show up, but not per-function values. Shrike points the app's OpenTelemetry SDK at itself when it runs the app; see fixtures/py-app for FastAPI, Flask and Django examples.

Quick start

Download

  1. Get Shrike-<version>-arm64.dmg from Releases and drag Shrike to Applications.
  2. Open Shrike. The build is signed and notarised by Apple, so it opens like any other app.
  3. Click Open the sample project, press Run, add a todo, and watch it break.

Linux (x64, arm64): there is no released build yet. Build an AppImage or .deb with scripts/release/build-linux.sh (see docs/RELEASING.md), or take the AppImage from the shrike-linux-x64 artifact of a CI run. Voice is macOS only. On NixOS, run the AppImage with appimage-run. Windows builds from the same config but hasn't been run on a Windows machine yet (docs/14-compatibility.md).

Run from source

git clone https://github.com/SumantxD/shrike.git
cd shrike
pnpm i
pnpm dev
Requirements
  • macOS on Apple Silicon (voice needs macOS 15 or later). Linux runs from source or a CI build, without voice
  • Node 24 (any Node from 22.18 runs your app; Shrike's own build uses 24)
  • pnpm 10 for running from source, plus Xcode if you want voice (the helper builds on first use)
  • Claude Code is optional. Shrike uses it on your own subscription when it's installed. Without it, the built-in agent runs on your own Anthropic API key, and the recording, Thread and API client work with no agent at all.

How it works

Your app's browser and server each run a small recorder. Shrike joins their events into one trip per click, strips secrets, stores it in .shrike/ and serves it to you and to your agent over MCP. Code changes come back only as a diff you approve.

  • packages/browser-agent runs in your page: clicks, fetches and React components with their source lines.
  • packages/node-agent loads into your server with --import: functions, queries, logs and errors, tied to the request that caused them.
  • packages/correlator joins both sides into one tree per click. packages/mcp-server hands it to agents as tools, with an approval gate on anything that changes code.
  • apps/desktop is the Electron app. apps/desktop/native/voice is the Swift voice helper.

More in docs/02-architecture.md and docs/05-agent.md.

How it compares

Shrike Browser devtools Sentry Postman / Bruno Claude Code on its own
Page, server and database in one trip per click ✅ Page only Traces, with an SDK Request only ❌
Real values on the line that ran ✅ Page, with breakpoints On errors ❌ ❌
Agent fix you approve, then a replay to prove it ✅ ❌ Paid AI add-on ❌ Fixes from reading code
Runs on your machine, no account ✅ ✅ Cloud or self-host Bruno yes, Postman needs an account ✅
Production monitoring ❌ ❌ ✅ ❌ ❌

Shrike is for building and debugging on your Mac. For errors in production, keep Sentry.

Privacy

  • No telemetry, no account. Your code, recordings and secrets stay on your Mac.
  • Secrets are stripped from every recording before it is stored, shown, sent to an agent or exported.
  • Agents can't edit files directly. Every change is a diff you approve.
  • Shrike connects out only when you ask: your agent's own API, voice model downloads from Hugging Face, and GitHub through your gh login.

Details in docs/07-security-privacy.md.

Roadmap

  • Notarised builds
  • Auto-update
  • Windows and Linux releases (Linux builds from source today)
  • Codex and OpenCode as agent brains
  • Shareable recordings (.shriketrace) and a read-only web viewer
  • Function steps for Python 3.12+ (FastAPI, Flask, Django)
  • More stacks: Vite SSR, SvelteKit, Nuxt, function steps for other OpenTelemetry backends

The full plan is in docs/08-roadmap.md.

Contributing

Shrike is built in the open and contributions are welcome, from a bug report to a new stack.

What changed in each version is in CHANGELOG.md. Everyone follows the Code of Conduct, and security problems go through SECURITY.md.

Star history

Star history chart for SumantxD/shrike

License

MIT. Copyright (c) 2026 Sumant Tirkey.


A shrike finds the bug and pins it to the thorn.

Yorumlar (0)

Sonuc bulunamadi