100% free AI setup guides — no credit card needed
← GitHub Projects
ADVANCEDFeatured0 views

Strix

Open-source AI penetration testing tool - autonomous AI hackers that run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept.

PythonDockerLLM AgentsOWASPCI/CD

What is this?

Strix is an open-source AI penetration testing tool. Autonomous AI hackers that run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept - not static-analysis false positives.

With 65k+ stars and an Apache-2.0 license, Strix brings agentic pentesting to developers and security teams: point it at a codebase, a GitHub repo, or a live web app, and a team of AI agents recon, exploit, and validate real vulnerabilities - then hand you actionable fixes.

What problem does it solve?

Traditional security testing is slow, expensive, and noisy:

Manual pentest:   Weeks of work, $10k+, report arrives after deploy
SAST scanner:    Thousands of findings, most false positives, no validation
Strix:           Hours, working PoCs, remediation guidance included

Static analyzers tell you where code looks suspicious. Strix tells you what is actually exploitable - because its agents run the app, attack it, and prove each finding with a working exploit.

How does it work?

Your target (code / repo / URL / API spec)
   │
   ▼
┌─────────────────────────────┐
│  Orchestrator               │
│  plans the engagement       │
└──────────┬──────────────────┘
           │
     ┌─────┼─────────────┐
     ▼     ▼             ▼
  Recon  Exploit    Post-exploit
  agent  agents     agents
     └─────┬─────────────┘
           ▼
   shared findings graph
   (vulns chained together)
           ▼
   validated PoC per finding
           ▼
┌─────────────────────────────┐
│  Report + remediation       │
│  CVSS, OWASP, fix patches   │
└─────────────────────────────┘
  1. You give Strix a target - a local directory, a GitHub repo, a live URL, or an OpenAPI/Postman spec.
  2. The orchestrator spins up a graph of specialized agents: recon, exploitation, post-exploitation.
  3. Agents share discoveries and chain vulnerabilities - like a real red team.
  4. Every finding is validated with a working proof-of-concept, scored (CVSS) and classified (OWASP).
  5. You get a compliance-ready report with remediation guidance - and optional auto-fix PRs.

Repository Structure

usestrix/strix/
├── strix/
│   ├── agents/            # Agent definitions & prompts
│   ├── config/            # Configuration
│   ├── core/              # Core engine
│   ├── interface/         # CLI, TUI, cloud, viewer
│   └── ...
├── skills/                # 9 agent skills (pentest, fix, CI, OWASP...)
├── containers/            # Sandbox Docker images
├── benchmarks/            # Performance benchmarks
├── docs/                  # Documentation
└── scripts/               # Utilities

Key Features

  • Agentic pentesting toolkit - HTTP interception proxy (Caido), browser exploitation, interactive shell, custom Python exploit runtime, recon/OSINT, SAST + DAST
  • Multi-agent orchestration - specialized agents for recon, exploitation, and post-exploitation that share discoveries and chain vulnerabilities
  • Real exploit validation - working PoCs, not false positives; every finding is proven
  • Comprehensive vulnerability coverage - OWASP Top 10 and beyond: injection, XSS, SSRF, XXE, RCE, broken access control, business logic flaws, API security, cloud misconfigurations
  • Developer-first CLI - strix --target ./app and go; actionable findings with remediation guidance
  • Auto-fix & reporting - AI-generated patches as ready-to-merge PRs; compliance-ready reports (SOC 2, ISO 27001, PCI DSS)
  • CI/CD integration - GitHub Actions workflow to scan every pull request and block insecure code
  • Agent-ready - 9 SKILL.md-compatible skills for Claude Code, Cursor, Codex (npx skills add usestrix/strix)
  • Local web viewer - strix view opens a dashboard with findings, live agent team map, and past runs

What You'll Learn

  • How AI agents perform real penetration testing (recon → exploit → validate)
  • How multi-agent orchestration works for security testing
  • How to validate vulnerabilities with working PoCs instead of trusting scanner output
  • How to integrate security testing into CI/CD pipelines
  • How to use agent skills to run pentests from your coding agent
  • How to read and act on CVSS-scored, OWASP-classified findings
securitypentestingai-agentsopen-sourcepythoncicdowaspred-teamingdevsecops

See it in action

Install and run your first scan:

# Install Strix
curl -sSL https://strix.ai/install | bash

# Configure your AI provider
export STRIX_LLM="openrouter/z-ai/glm-5.3"
export LLM_API_KEY="your-api-key"

# Run your first security assessment
strix --target ./app-directory

More targets:

# Security review of a GitHub repository
strix --target https://github.com/org/repo

# Black-box web application assessment
strix --target https://your-app.com

# API testing with an OpenAPI spec
strix --target ./openapi.yaml --target https://api.your-app.com

# Headless mode for CI (exits non-zero when vulns found)
strix -n --target https://your-app.com

Open the results in the local viewer:

strix view

Try Strix Cloud for no-setup pentesting with one-click autofix, or the docs for the full CLI reference.

View Demo

Want to learn more about this project?

Have questions or want to understand this technology more deeply? Send me a message.

Related Projects

Discussion

Leave a Comment

Loading comments...