strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Strix is an agent skill that equips AI coding assistants with autonomous penetration testing capabilities to identify and validate security vulnerabilities in applications. It provides four distinct skills—penetration-testing-with-strix for headless local scans, managed-pentesting-with-strix for cloud-based testing, fix-security-vulnerabilities-with-strix for automated remediation, and ci-security-scanning-with-strix for pull request security checks. The skill works with SKILL.md-compatible agents like Claude Code, Cursor, and Codex, enabling them to run security assessments, generate proof-of-concept exploits, and apply automated fixes without requiring developers to manually configure Docker or LLM keys.
Key Features
Use Cases
- 01Enable Claude Code or Cursor to run penetration tests on codebases and web applications during development
- 02Automate bug bounty research by having AI agents discover vulnerabilities and generate proof-of-concept exploits
- 03Integrate security scanning into pull request workflows to block vulnerable code before production
- 04Perform authenticated grey-box testing by instructing agents to test applications with specific credentials
- 05Validate API security by pointing agents at OpenAPI/Swagger specifications or Postman collections
- 06Generate compliance-ready penetration testing reports for SOC 2, ISO 27001, or PCI DSS audits
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
strix — FAQ
What is the Strix agent skill?+
Strix is an agent skill that adds penetration testing capabilities to AI coding assistants like Claude Code, Cursor, and Codex. It allows agents to autonomously scan applications for security vulnerabilities, validate them with working exploits, and generate fixes.
How do I install the Strix agent skill?+
Run 'npx skills add usestrix/strix' in your project directory to install the skill for SKILL.md-compatible agents. This adds four skills: penetration-testing-with-strix, managed-pentesting-with-strix, fix-security-vulnerabilities-with-strix, and ci-security-scanning-with-strix.
Which AI clients work with Strix?+
Strix works with any SKILL.md-compatible agent including Claude Code, Cursor, Codex, and similar coding assistants. Agents can invoke Strix either locally via the CLI or through the managed cloud API.
Do I need API keys or Docker to use Strix?+
For local CLI usage, you need Docker running and an LLM API key from supported providers like OpenAI, Anthropic, or Google. The managed-pentesting-with-strix skill uses the cloud platform and doesn't require local Docker or API keys.
Is Strix free to use?+
The open-source Strix CLI is free under the Apache 2.0 license, though you'll need to provide your own LLM API credits. The managed cloud platform at app.strix.ai offers a free tier with additional paid features for continuous pentesting and enterprise controls.
Can Strix scan both code repositories and live web applications?+
Yes, Strix supports multiple target types including local directories, GitHub repositories, live web applications, and API specifications (OpenAPI/Swagger/Postman). Agents can perform white-box, grey-box, or black-box testing depending on what information is provided.
How do I install strix?+
Open the source repository on GitHub and follow its README. strix is a skill — MCP Agents Market links you directly to the official repo.
Is strix free?+
strix is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.