Skip to content
Code Recycle
Free · open sourceApache-2.0Unclaimed listing

strix is by usestrix — not by us.

We indexed this project so people can find it. We are not selling it, we host no copy of the code, and we are not affiliated with or endorsed by its authors — get it from them.

Indexed Sep 19, 2026 · 63,709 stars at index time. Maintainers: claiming verifies your identity and unlocks a higher assurance tier. Removal requests are honored.

Workflow · for humans & their agents

strix

unclaimed listingactively maintainedFreeApache-2.0

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

by Open Source Community · New publisher

Go to the project ↗Open live demo ↗

Every claim on this page is refundable if it is untrue — refund policy.

strix.ai

usestrix/strix is an open-source project by usestrix: Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.. Indexed here so it can be found — not resold.

It is free. Get it from the upstream repository: https://github.com/usestrix/strix

From the project's own README (excerpt, reproduced for discovery under its Apache-2.0 license):

Strix

The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities.

> New! Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - Get started with no setup required.

---

Strix Overview

Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.

Key Capabilities: • Full pentesting toolkit - reconnaissance, exploitation, and validation out of the box • Multi-agent orchestration - teams of AI pentesters that collaborate and scale • Real exploit validation - working PoCs, not false positives like legacy vulnerability scanners • Developer‑first CLI - actionable findings with remediation guidance • Auto‑fix & reporting - generate patches and compliance-ready pentest reports

Use Cases • Application Security Testing - Detect and validate critical vulnerabilities in your applications • Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports • Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting • CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production

🚀 Quick Start

Prerequisites: • Docker (running) • An LLM API key from any supported provider (OpenAI, Anthropic, Google, etc.)

Installation & First Scan

> First run automatically pulls the sandbox Docker image. Results are…

Preview

See what it does before you commit. Previews show behavior, never source code.

01Capabilities

Does

  • No capabilities recorded

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

python

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

This listing is unclaimed, so publisher identity cannot be verified and it stays below the “verified” tier by design — that is a statement about the listing, not about the project’s quality. Our automated scans still ran; a maintainer who claims it unlocks identity verification.

VersionChannelReleasedNotes
0.0.0stableSep 19, 2026Indexed listing — see the upstream repository for real release history.