Strix
Open-source AI penetration testing tool - autonomous AI hackers that run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept.
What is this?
Strix is an open-source AI penetration testing tool. Autonomous AI hackers that run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept - not static-analysis false positives.
With 65k+ stars and an Apache-2.0 license, Strix brings agentic pentesting to developers and security teams: point it at a codebase, a GitHub repo, or a live web app, and a team of AI agents recon, exploit, and validate real vulnerabilities - then hand you actionable fixes.
What problem does it solve?
Traditional security testing is slow, expensive, and noisy:
Manual pentest: Weeks of work, $10k+, report arrives after deploy
SAST scanner: Thousands of findings, most false positives, no validation
Strix: Hours, working PoCs, remediation guidance included
Static analyzers tell you where code looks suspicious. Strix tells you what is actually exploitable - because its agents run the app, attack it, and prove each finding with a working exploit.
How does it work?
Your target (code / repo / URL / API spec)
│
▼
┌─────────────────────────────┐
│ Orchestrator │
│ plans the engagement │
└──────────┬──────────────────┘
│
┌─────┼─────────────┐
▼ ▼ ▼
Recon Exploit Post-exploit
agent agents agents
└─────┬─────────────┘
▼
shared findings graph
(vulns chained together)
▼
validated PoC per finding
▼
┌─────────────────────────────┐
│ Report + remediation │
│ CVSS, OWASP, fix patches │
└─────────────────────────────┘
- You give Strix a target - a local directory, a GitHub repo, a live URL, or an OpenAPI/Postman spec.
- The orchestrator spins up a graph of specialized agents: recon, exploitation, post-exploitation.
- Agents share discoveries and chain vulnerabilities - like a real red team.
- Every finding is validated with a working proof-of-concept, scored (CVSS) and classified (OWASP).
- You get a compliance-ready report with remediation guidance - and optional auto-fix PRs.
Repository Structure
usestrix/strix/
├── strix/
│ ├── agents/ # Agent definitions & prompts
│ ├── config/ # Configuration
│ ├── core/ # Core engine
│ ├── interface/ # CLI, TUI, cloud, viewer
│ └── ...
├── skills/ # 9 agent skills (pentest, fix, CI, OWASP...)
├── containers/ # Sandbox Docker images
├── benchmarks/ # Performance benchmarks
├── docs/ # Documentation
└── scripts/ # Utilities
Key Features
- Agentic pentesting toolkit - HTTP interception proxy (Caido), browser exploitation, interactive shell, custom Python exploit runtime, recon/OSINT, SAST + DAST
- Multi-agent orchestration - specialized agents for recon, exploitation, and post-exploitation that share discoveries and chain vulnerabilities
- Real exploit validation - working PoCs, not false positives; every finding is proven
- Comprehensive vulnerability coverage - OWASP Top 10 and beyond: injection, XSS, SSRF, XXE, RCE, broken access control, business logic flaws, API security, cloud misconfigurations
- Developer-first CLI -
strix --target ./appand go; actionable findings with remediation guidance - Auto-fix & reporting - AI-generated patches as ready-to-merge PRs; compliance-ready reports (SOC 2, ISO 27001, PCI DSS)
- CI/CD integration - GitHub Actions workflow to scan every pull request and block insecure code
- Agent-ready - 9 SKILL.md-compatible skills for Claude Code, Cursor, Codex (
npx skills add usestrix/strix) - Local web viewer -
strix viewopens a dashboard with findings, live agent team map, and past runs
What You'll Learn
- How AI agents perform real penetration testing (recon → exploit → validate)
- How multi-agent orchestration works for security testing
- How to validate vulnerabilities with working PoCs instead of trusting scanner output
- How to integrate security testing into CI/CD pipelines
- How to use agent skills to run pentests from your coding agent
- How to read and act on CVSS-scored, OWASP-classified findings
See it in action
Install and run your first scan:
# Install Strix
curl -sSL https://strix.ai/install | bash
# Configure your AI provider
export STRIX_LLM="openrouter/z-ai/glm-5.3"
export LLM_API_KEY="your-api-key"
# Run your first security assessment
strix --target ./app-directory
More targets:
# Security review of a GitHub repository
strix --target https://github.com/org/repo
# Black-box web application assessment
strix --target https://your-app.com
# API testing with an OpenAPI spec
strix --target ./openapi.yaml --target https://api.your-app.com
# Headless mode for CI (exits non-zero when vulns found)
strix -n --target https://your-app.com
Open the results in the local viewer:
strix view
Try Strix Cloud for no-setup pentesting with one-click autofix, or the docs for the full CLI reference.
Want to learn more about this project?
Have questions or want to understand this technology more deeply? Send me a message.
Related Projects
Laya
Open-source System 1 decision engine - typed choice, score and yes/no decisions over any text in a single forward pass, in 100+ languages, with a router that picks the right checkpoint per request. A self-hosted, Jev-compatible alternative.
Cua
Give AI agents computers they can use — open-source desktop automation drivers, isolated cloud desktops, local macOS VMs, and benchmarks for computer-use agents.
OpenWorker
Open-source AI coworker that lives on your desktop and delivers finished work — security reviews, documents, Slack replies — with your own model and 25+ integrations.
Discussion
Loading comments...