</>MCP Agents Market
Skill

strix

by usestrix53.4kPythonUpdated 2026-08-14

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Claude CodeCursorCodex

Strix is an agent skill that equips AI coding assistants with autonomous penetration testing capabilities to identify and validate security vulnerabilities in applications. It provides four distinct skills—penetration-testing-with-strix for headless local scans, managed-pentesting-with-strix for cloud-based testing, fix-security-vulnerabilities-with-strix for automated remediation, and ci-security-scanning-with-strix for pull request security checks. The skill works with SKILL.md-compatible agents like Claude Code, Cursor, and Codex, enabling them to run security assessments, generate proof-of-concept exploits, and apply automated fixes without requiring developers to manually configure Docker or LLM keys.

Key Features

Four specialized agent skills for local pentesting, managed cloud scanning, vulnerability remediation, and CI/CD integration
Multi-agent orchestration with distributed AI pentesters that collaborate on reconnaissance, exploitation, and validation
Real exploit validation with working proof-of-concept code instead of false-positive-prone static analysis
Comprehensive vulnerability coverage including OWASP Top 10, injection attacks, broken access control, and business logic flaws
Full offensive security toolkit with HTTP proxy, browser automation, shell access, and custom exploit runtime
Auto-fix capability that generates security patches as ready-to-merge pull requests
Flexible deployment supporting both open-source CLI (local Docker) and managed cloud platform via REST API
CI/CD-native with GitHub Actions integration for automated pull request security scanning

Use Cases

  • 01Enable Claude Code or Cursor to run penetration tests on codebases and web applications during development
  • 02Automate bug bounty research by having AI agents discover vulnerabilities and generate proof-of-concept exploits
  • 03Integrate security scanning into pull request workflows to block vulnerable code before production
  • 04Perform authenticated grey-box testing by instructing agents to test applications with specific credentials
  • 05Validate API security by pointing agents at OpenAPI/Swagger specifications or Postman collections
  • 06Generate compliance-ready penetration testing reports for SOC 2, ISO 27001, or PCI DSS audits

Related Skills

View more

strix — FAQ

What is the Strix agent skill?+

Strix is an agent skill that adds penetration testing capabilities to AI coding assistants like Claude Code, Cursor, and Codex. It allows agents to autonomously scan applications for security vulnerabilities, validate them with working exploits, and generate fixes.

How do I install the Strix agent skill?+

Run 'npx skills add usestrix/strix' in your project directory to install the skill for SKILL.md-compatible agents. This adds four skills: penetration-testing-with-strix, managed-pentesting-with-strix, fix-security-vulnerabilities-with-strix, and ci-security-scanning-with-strix.

Which AI clients work with Strix?+

Strix works with any SKILL.md-compatible agent including Claude Code, Cursor, Codex, and similar coding assistants. Agents can invoke Strix either locally via the CLI or through the managed cloud API.

Do I need API keys or Docker to use Strix?+

For local CLI usage, you need Docker running and an LLM API key from supported providers like OpenAI, Anthropic, or Google. The managed-pentesting-with-strix skill uses the cloud platform and doesn't require local Docker or API keys.

Is Strix free to use?+

The open-source Strix CLI is free under the Apache 2.0 license, though you'll need to provide your own LLM API credits. The managed cloud platform at app.strix.ai offers a free tier with additional paid features for continuous pentesting and enterprise controls.

Can Strix scan both code repositories and live web applications?+

Yes, Strix supports multiple target types including local directories, GitHub repositories, live web applications, and API specifications (OpenAPI/Swagger/Postman). Agents can perform white-box, grey-box, or black-box testing depending on what information is provided.

How do I install strix?+

Open the source repository on GitHub and follow its README. strix is a skill — MCP Agents Market links you directly to the official repo.

Is strix free?+

strix is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches