Daggler
A semantic IDE for GitHub Actions: typed IR, live job graph, five validation layers, and rules that catch prompt injection into AI agents.

The semantic workbench for GitHub Actions.
GitHub Actions workflows are code that runs with your secrets, and most of us edit them as untyped YAML and find out what's wrong by pushing. Daggler parses them into a typed model and gives them an IDE: a live job graph, Monaco YAML with diagnostics on the exact span, an inspector, one-click fixes and a security grade.

The pipeline
Workflow YAML becomes a typed intermediate representation (jobs, steps, triggers, permissions, matrix, concurrency, outputs) with a byte-level source map, then a job dependency graph with cycle and unreachable-job detection. Five validation layers run over it, from the parser and schema through expression contexts and graph semantics to known action inputs, plus a 13-rule policy engine. Edits made in the graph, the inspector or the AI assistant become structured patches on the original text, so your comments and formatting survive. The whole pipeline is plain TypeScript shared by the browser, the CLI and the worker, so there's no validation server.
Workflows that run agents
Three of the rules are about agentic workflows:
- AGENT001 flags attacker-controlled issue or PR text flowing into an AI agent's prompt on a privileged trigger.
- AGENT002 flags agents with more permissions than they need.
- AGENT003 flags a workflow that executes the agent's output.

A sample "Triage Agent" workflow that interpolates the issue body into the prompt and gives the agent shell and write tools: graded F, 20 out of 100.
The ordinary supply-chain rules are there too, like flagging actions that aren't pinned to a commit SHA, with a quick fix that pins them to real SHAs from its action catalog.
A confidence ladder that never fakes results
Static analysis runs on every keystroke. The next rung runs the workflow locally with act in Docker and streams it into the editor's Run panel. The top rung dispatches to GitHub itself. Every result is labelled as simulated or proved, and a rung that isn't connected says so instead of returning something plausible.

There's also a daggler CLI: lint, map, search, and logs, which maps a failed run's logs back to the workflow lines that caused them.
Status
One overnight sprint on 3 and 4 June 2026: 16 commits, MIT, CI green. It's designed to be self-hosted, but there's no hosted instance or packaged release, so you run it locally. The AI assistant (explain, harden, generate) needs your own Anthropic API key, and the GitHub App and webhook layer landed in the last commit, so treat it as early. The architecture doc is the best place to start.