usestrix

10 mods across 1 repository, 59k stars between them.

strix AGENTS.md

01

usestrix/strix

Instructions file CodexOpenCode

Instructions for usestrix/strix, covering strix — agent guide, using strix from an agent and contributing to this repo.

59k 3d ago C 1,010 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object…

59k 3d ago A 144 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Application security testing (AppSec) across a whole product with Strix — decide which asset needs which test (source code, running web app, API, CI pipeline), run it, and turn the results into a ranked remediation plan. Autonomous agents exploit and prove each issue instead of emitting static-analysis alerts, so the…

59k 3d ago A 125 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results as PR comments and SARIF uploaded to code scanning. Covers both the self-hosted open-source CLI (runs in your runner)…

59k 3d ago B 140 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Find security vulnerabilities in a codebase or repository with Strix — a white-box AI security review that reads your source, reasons about the actual data flow and authorization model, then exploits what it finds in a live sandbox so every reported issue has a working proof-of-concept instead of a noisy…

59k 3d ago A 129 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use…

59k 3d ago A 124 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Run a managed pentest of a web app or API through the app.strix.ai REST API — no local Docker, LLM key, or install needed. Create an API token, register domain/repository assets, launch and poll scans, triage vulnerabilities, export SARIF, download PDF/DOCX pentest reports for SOC 2 and other compliance evidence…

59k 3d ago A 139 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design…

59k 3d ago A 151 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP Top 10 and beyond — injection, XSS, SSRF, auth/access-control flaws, IDOR, business logic) instead of just flagging them. Runs self-hosted with the open-source…

59k 3d ago B 146 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature…

59k 3d ago A 129 tokens original Apache-2.0