strix is by usestrix — not by us.
We indexed this project so people can find it. We are not selling it, we host no copy of the code, and we are not affiliated with or endorsed by its authors — get it from them.
Indexed Sep 19, 2026 · 63,709 stars at index time. Maintainers: claiming verifies your identity and unlocks a higher assurance tier. Removal requests are honored.
Workflow · for humans & their agents
strix
unclaimed listingactively maintainedFreeApache-2.0
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
by Open Source Community · New publisher
Every claim on this page is refundable if it is untrue — refund policy.
usestrix/strix is an open-source project by usestrix: Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.. Indexed here so it can be found — not resold.
It is free. Get it from the upstream repository: https://github.com/usestrix/strix
From the project's own README (excerpt, reproduced for discovery under its Apache-2.0 license):
Strix
The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities.
> New! Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - Get started with no setup required.
---
Strix Overview
Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.
Key Capabilities: • Full pentesting toolkit - reconnaissance, exploitation, and validation out of the box • Multi-agent orchestration - teams of AI pentesters that collaborate and scale • Real exploit validation - working PoCs, not false positives like legacy vulnerability scanners • Developer‑first CLI - actionable findings with remediation guidance • Auto‑fix & reporting - generate patches and compliance-ready pentest reports
Use Cases • Application Security Testing - Detect and validate critical vulnerabilities in your applications • Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports • Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting • CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production
🚀 Quick Start
Prerequisites: • Docker (running) • An LLM API key from any supported provider (OpenAI, Anthropic, Google, etc.)
Installation & First Scan
> First run automatically pulls the sandbox Docker image. Results are…
Preview
See what it does before you commit. Previews show behavior, never source code.
01Capabilities
Does
- No capabilities recorded
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 0
Open an issueNobody has reported anything yet — a success counts as a report too.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
This listing is unclaimed, so publisher identity cannot be verified and it stays below the “verified” tier by design — that is a statement about the listing, not about the project’s quality. Our automated scans still ran; a maintainer who claims it unlocks identity verification.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.0.0 | stable | Sep 19, 2026 | Indexed listing — see the upstream repository for real release history. |