usestrix/strixPublic

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

AI summary: An open-source AI penetration testing tool utilizing autonomous agents to find and exploit app vulnerabilities.

Stars
66.3K
+589 today
Forks
7.3K
Watchers
293
Open issues
176
Open PRs
232
Contributors
~71
Commits
818
Branches
154

PythonApache-2.0Created Aug 5, 2025Last push 1d agoLatest release v1.6.2+1.7K stars this week+6K this month

Quick answers

What is strix?
An open-source AI penetration testing tool utilizing autonomous agents to find and exploit app vulnerabilities.
What does strix do?
Strix is an open-source security tool that deploys autonomous AI agents to conduct dynamic penetration testing on applications. It moves beyond standard static analysis by actively attempting to exploit discovered vulnerabilities, generating working proof-of-concept exploits to eliminate false positives. The platform provides highly actionable remediation steps formatted specifically for developers, surfacing them directly in the terminal or CI/CD logs. By supporting distributed multi-agent orchestration, it can scale to simulate complex, chained attack scenarios across large codebases. It embeds natively into GitHub Actions to block insecure code before deployment.
Who is strix for?
Developers, security teams, and ethical hackers aiming to automate and scale penetration testing capabilities. Requires familiarity with penetration testing concepts, Docker, and LLM APIs.
How do I get started with strix?
curl -sSL https://strix.ai/install | bash
How popular is strix on GitHub?
usestrix/strix has 66,273 stars and 7,265 forks on GitHub, and gained 1,669 stars in the last 7 days.
What license does strix use?
usestrix/strix is released under the Apache-2.0 license.

Star history

since Jul 27, 2026
020K40K60KJul 2026Aug 2026Sep 2026Oct 2026
66.3K stars as of Oct 3, 2026. Measured daily since Jul 27, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-28: 2 commits2025-09-29: 1 commit2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 1 commit2025-10-11: 0 commits2025-10-12: 1 commit2025-10-13: 3 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 6 commits2025-10-19: 0 commits2025-10-20: 2 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 4 commits2025-10-30: 2 commits2025-10-31: 6 commits2025-11-01: 7 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 2 commits2025-11-06: 0 commits2025-11-07: 1 commit2025-11-08: 1 commit2025-11-09: 0 commits2025-11-10: 2 commits2025-11-11: 0 commits2025-11-12: 5 commits2025-11-13: 2 commits2025-11-14: 4 commits2025-11-15: 5 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 1 commit2025-11-22: 3 commits2025-11-23: 2 commits2025-11-24: 1 commit2025-11-25: 3 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 1 commit2025-11-30: 0 commits2025-12-01: 2 commits2025-12-02: 2 commits2025-12-03: 5 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 5 commits2025-12-07: 7 commits2025-12-08: 1 commit2025-12-09: 2 commits2025-12-10: 0 commits2025-12-11: 1 commit2025-12-12: 2 commits2025-12-13: 1 commit2025-12-14: 6 commits2025-12-15: 6 commits2025-12-16: 2 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 1 commit2026-01-02: 0 commits2026-01-03: 3 commits2026-01-04: 2 commits2026-01-05: 8 commits2026-01-06: 9 commits2026-01-07: 7 commits2026-01-08: 13 commits2026-01-09: 14 commits2026-01-10: 11 commits2026-01-11: 1 commit2026-01-12: 1 commit2026-01-13: 3 commits2026-01-14: 9 commits2026-01-15: 6 commits2026-01-16: 11 commits2026-01-17: 3 commits2026-01-18: 4 commits2026-01-19: 12 commits2026-01-20: 7 commits2026-01-21: 5 commits2026-01-22: 3 commits2026-01-23: 7 commits2026-01-24: 0 commits2026-01-25: 1 commit2026-01-26: 0 commits2026-01-27: 1 commit2026-01-28: 1 commit2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 1 commit2026-02-01: 3 commits2026-02-02: 0 commits2026-02-03: 1 commit2026-02-04: 1 commit2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 2 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 2 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 2 commits2026-02-16: 0 commits2026-02-17: 2 commits2026-02-18: 0 commits2026-02-19: 7 commits2026-02-20: 10 commits2026-02-21: 1 commit2026-02-22: 4 commits2026-02-23: 3 commits2026-02-24: 0 commits2026-02-25: 1 commit2026-02-26: 1 commit2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 3 commits2026-03-03: 2 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 2 commits2026-03-09: 1 commit2026-03-10: 0 commits2026-03-11: 2 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 2 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 1 commit2026-03-18: 0 commits2026-03-19: 5 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 7 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 2 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 1 commit2026-04-13: 1 commit2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 0 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 2 commits2026-04-23: 2 commits2026-04-24: 3 commits2026-04-25: 54 commits2026-04-26: 27 commits2026-04-27: 1 commit2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 3 commits2026-05-04: 5 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 1 commit2026-05-20: 0 commits2026-05-21: 1 commit2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 3 commits2026-05-25: 14 commits2026-05-26: 4 commits2026-05-27: 0 commits2026-05-28: 1 commit2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 6 commits2026-06-08: 13 commits2026-06-09: 4 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 0 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 1 commit2026-06-17: 0 commits2026-06-18: 0 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 2 commits2026-06-23: 0 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 5 commits2026-06-30: 2 commits2026-07-01: 0 commits2026-07-02: 2 commits2026-07-03: 6 commits2026-07-04: 2 commits2026-07-05: 0 commits2026-07-06: 6 commits2026-07-07: 4 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 10 commits2026-07-11: 1 commit2026-07-12: 7 commits2026-07-13: 7 commits2026-07-14: 4 commits2026-07-15: 2 commits2026-07-16: 14 commits2026-07-17: 5 commits2026-07-18: 4 commits2026-07-19: 1 commit2026-07-20: 4 commits2026-07-21: 6 commits2026-07-22: 11 commits2026-07-23: 0 commits2026-07-24: 4 commits2026-07-25: 13 commits2026-07-26: 11 commits2026-07-27: 9 commits2026-07-28: 1 commit2026-07-29: 2 commits2026-07-30: 4 commits2026-07-31: 2 commits2026-08-01: 11 commits2026-08-02: 6 commits2026-08-03: 1 commit2026-08-04: 8 commits2026-08-05: 3 commits2026-08-06: 15 commits2026-08-07: 4 commits2026-08-08: 2 commits2026-08-09: 10 commits2026-08-10: 5 commits2026-08-11: 1 commit2026-08-12: 0 commits2026-08-13: 0 commits2026-08-14: 4 commits2026-08-15: 0 commits2026-08-16: 0 commits2026-08-17: 8 commits2026-08-18: 1 commit2026-08-19: 7 commits2026-08-20: 7 commits2026-08-21: 2 commits2026-08-22: 0 commits2026-08-23: 0 commits2026-08-24: 2 commits2026-08-25: 2 commits2026-08-26: 4 commits2026-08-27: 1 commit2026-08-28: 4 commits2026-08-29: 0 commits2026-08-30: 1 commit2026-08-31: 4 commits2026-09-01: 9 commits2026-09-02: 17 commits2026-09-03: 2 commits2026-09-04: 6 commits2026-09-05: 5 commits2026-09-06: 1 commit2026-09-07: 0 commits2026-09-08: 0 commits2026-09-09: 1 commit2026-09-10: 1 commit2026-09-11: 0 commits2026-09-12: 0 commits2026-09-13: 1 commit2026-09-14: 0 commits2026-09-15: 1 commit2026-09-16: 2 commits2026-09-17: 2 commits2026-09-18: 4 commits2026-09-19: 0 commits2026-09-20: 1 commit2026-09-21: 0 commits2026-09-22: 2 commits2026-09-23: 2 commits2026-09-24: 0 commits2026-09-25: 0 commits2026-09-26: 0 commits
789 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Landmark project

    66,273 stars

  • High momentum

    +589 stars today

  • Very active

    789 commits in 52 weeks

  • Permissive license

    Apache-2.0

  • Continuous integration

    Automated checks passing

  • Repeat trending

    24 trending appearances

What strix does

Strix is an open-source security tool that deploys autonomous AI agents to conduct dynamic penetration testing on applications. It moves beyond standard static analysis by actively attempting to exploit discovered vulnerabilities, generating working proof-of-concept exploits to eliminate false positives. The platform provides highly actionable remediation steps formatted specifically for developers, surfacing them directly in the terminal or CI/CD logs. By supporting distributed multi-agent orchestration, it can scale to simulate complex, chained attack scenarios across large codebases. It embeds natively into GitHub Actions to block insecure code before deployment.

Developers, security teams, and ethical hackers aiming to automate and scale penetration testing capabilities. Requires familiarity with penetration testing concepts, Docker, and LLM APIs.

  • Autonomous Agents: Deploys AI-driven bots for continuous reconnaissance, dynamic exploitation, and vulnerability validation.
  • Exploit Generation: Automatically crafts working proof-of-concept exploits to definitively confirm the existence of vulnerabilities.
  • Developer UX: Surfaces actionable findings and clear, code-level remediation guidance directly within the CLI.
  • Distributed Orchestration: Coordinates multiple AI agents to execute sophisticated attack chains and distributed security testing.
  • CI/CD Integration: Embeds natively into workflows like GitHub Actions to automatically fail builds upon detecting critical flaws.

Where teams use it

Continuous Security Testing

Security teams automate scanning for critical vulnerabilities, receiving validated findings without the overhead of manual verification.

Bug Bounty Automation

Ethical hackers deploy the agents to accelerate vulnerability discovery and automate the creation of PoCs for faster reporting.

Secure Pipelines

DevOps teams integrate workflows into their CI pipelines to automatically block pull requests introducing exploitable vulnerabilities.

Compliance Penetration Testing

Organizations rapidly perform comprehensive penetration tests in hours to satisfy security compliance and audit requirements.

Getting started: curl -sSL https://strix.ai/install | bash

README

main branch

Strix Banner

Strix

The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities.


Docs Website

Strix Cloud Try Strix Enterprise

Ask DeepWiki GitHub Stars License PyPI Version

Join Discord Follow on X

usestrix%2Fstrix | Trendshift usestrix/strix | Trendshift

Tip

New! Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - Get started with no setup required.


Strix Overview

Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.

Key Capabilities:

  • Full pentesting toolkit - reconnaissance, exploitation, and validation out of the box
  • Multi-agent orchestration - teams of AI pentesters that collaborate and scale
  • Real exploit validation - working PoCs, not false positives like legacy vulnerability scanners
  • Developer‑first CLI - actionable findings with remediation guidance
  • Auto‑fix & reporting - generate patches and compliance-ready pentest reports

Use Cases

  • Application Security Testing - Detect and validate critical vulnerabilities in your applications
  • Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports
  • Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting
  • CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production

🚀 Quick Start

Prerequisites:

  • Docker (running)
  • An LLM API key from any supported provider (OpenAI, Anthropic, Google, etc.)

Installation & First Scan

# Install Strix
curl -sSL https://strix.ai/install | bash

# Configure your AI provider
export STRIX_LLM="openrouter/z-ai/glm-5.3"
export LLM_API_KEY="your-api-key"

# Run your first security assessment
strix --target ./app-directory

Note

First run automatically pulls the sandbox Docker image. Results are saved to strix_runs/<run-name>


Ways to Run Strix

  • Open Source - free, runs locally with Docker and your own LLM key. Quick Start
  • Strix Cloud - no setup, validated findings, one-click autofix, and PR reviews. Run a pentest →
  • Enterprise - SSO, compliance-ready reports, VPC or self-hosted deployment. Try Strix Enterprise →

☁️ Strix Cloud

Try the Strix full-stack penetration testing platform at app.strix.ai - sign up for free, connect your repos and domains, and launch a pentest in minutes.

  • Validated findings with PoCs - every vulnerability includes a working proof-of-concept exploit and reproduction steps
  • One-click autofix - AI-generated security patches as ready-to-merge pull requests
  • Continuous pentesting - always-on vulnerability scanning that keeps pace with your deployments
  • DevSecOps integrations - GitHub, GitLab, Bitbucket, Slack, Jira, Linear, and CI/CD pipelines
  • Continuous learning - AI that builds on past findings, adapts to your codebase, and reduces false positives over time

Run a pentest →

🏢 Enterprise

Get the same Strix experience with enterprise-grade controls: SSO (SAML/OIDC), custom compliance-ready penetration testing reports (SOC 2, ISO 27001, PCI DSS), dedicated support and SLA, custom deployment options (VPC or self-hosted), BYOK model support, and tailored AI pentesting agents optimized for your environment.

Try Strix Enterprise →


🤖 Use Strix from Your Coding Agent

Strix is agent-ready. Give Claude Code, Cursor, Codex, or any SKILL.md-compatible agent the ability to run pentests, fix findings, and set up CI scanning:

npx skills add usestrix/strix

This installs nine skills for running pentests, fixing findings, and CI scanning, against code, web apps, APIs, and the OWASP Top 10. Agents can use the local CLI or the managed cloud with the same engine.

See AGENTS.md for the quick reference, docs.strix.ai/llms.txt for the CLI, and docs.app.strix.ai for the API.


✨ Features

Agentic Pentesting Tools

Strix agents come equipped with a comprehensive offensive security toolkit - the same tools used by professional penetration testers and ethical hackers:

  • HTTP Interception Proxy - Full request/response manipulation and analysis with Caido
  • Browser Exploitation - Automated browser for testing XSS, CSRF, clickjacking, and auth bypass flows
  • Shell & Command Execution - Interactive terminal for exploit development and post-exploitation
  • Custom Exploit Runtime - Python sandbox for writing and validating proof-of-concept exploits
  • Reconnaissance & OSINT - Automated attack surface mapping, subdomain enumeration, and fingerprinting
  • Static & Dynamic Code Analysis - SAST + DAST capabilities for comprehensive application security testing
  • Vulnerability Knowledge Base - Structured findings with CVSS scoring and OWASP classification

Comprehensive Vulnerability Scanner

Strix identifies, validates, and exploits a wide range of security vulnerabilities across the OWASP Top 10 and beyond:

  • Broken Access Control - IDOR, privilege escalation, auth bypass
  • Injection Attacks - SQL injection, NoSQL injection, OS command injection, SSTI
  • Server-Side Vulnerabilities - SSRF, XXE, insecure deserialization, RCE
  • Client-Side Attacks - XSS (stored/reflected/DOM), prototype pollution, CSRF
  • Business Logic Flaws - Race conditions, payment manipulation, workflow bypass
  • Authentication & Session - JWT attacks, session fixation, credential stuffing vectors
  • Infrastructure & Cloud - Misconfigurations, exposed services, cloud security issues
  • API Security - Broken authentication, mass assignment, rate limiting bypass

Graph of Agents (Multi-Agent Pentesting)

Advanced multi-agent orchestration for comprehensive automated penetration testing:

  • Distributed Pentesting - Specialized AI agents for recon, exploitation, and post-exploitation
  • Scalable Security Testing - Parallel execution across multiple targets for fast, comprehensive coverage
  • Dynamic Coordination - Agents share discoveries, chain vulnerabilities, and collaborate like a red team

🖥️ Local Web Viewer

Every scan writes its results to disk as it runs. Bring them up in a local dashboard with a single command:

# Open the most recent run
strix view

# ...or open a specific run by name
strix view my-run-name

# Expose the viewer on all IPv4 interfaces at a fixed port
strix view --host 0.0.0.0 --port 8080 --no-open

The dashboard shows the findings, a live map of the agent team, and past runs. Nothing leaves your machine, and the UI ships prebuilt. strix view binds to 127.0.0.1 and prints a tokened link that grants access to the run, so share it carefully.

See the viewer documentation for the options and for reaching the viewer from another machine.


Usage Examples

Basic Usage

# Scan a local codebase
strix --target ./app-directory

# Security review of a GitHub repository
strix --target https://github.com/org/repo

# Black-box web application assessment
strix --target https://your-app.com

API Testing (OpenAPI / Swagger / Postman)

Point Strix at an API contract and it tests every declared endpoint instead of having to discover them by crawling. Pair the spec with the live base URL so the agent knows where to send traffic:

# OpenAPI / Swagger file, Postman export, or a live collection by id
strix --target ./openapi.yaml --target https://api.your-app.com
strix --target postman://<collection-uuid> --target https://api.your-app.com

Advanced Testing Scenarios

# Grey-box authenticated testing
strix --target https://your-app.com --instruction "Perform authenticated testing using credentials: user:pass"

# Multi-target testing (source code + deployed app)
strix -t https://github.com/org/app -t https://your-app.com

# Targets from a file, one target per non-empty, non-comment line
strix --target-list ./targets.txt

See the CLI reference for every option, including scan modes, diff scope, instruction files, and budgets.

Headless Mode

Run Strix programmatically without interactive UI using the -n/--non-interactive flag - perfect for servers and automated jobs. The CLI prints real-time vulnerability findings and the final report before exiting. Exits with non-zero code when vulnerabilities are found.

strix -n --target https://your-app.com

CI/CD (GitHub Actions)

Strix can be added to your pipeline to run a security test on pull requests with a lightweight GitHub Actions workflow:

name: strix-penetration-test

on:
  pull_request:

jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
        with:
          fetch-depth: 0

      - name: Install Strix
        run: curl -sSL https://strix.ai/install | bash

      - name: Run Strix
        env:
          STRIX_LLM: ${{ secrets.STRIX_LLM }}
          LLM_API_KEY: ${{ secrets.LLM_API_KEY }}

        run: strix -n -t ./ --scan-mode quick

Tip

In CI pull request runs, Strix automatically scopes quick reviews to changed files, which is why the checkout above fetches full history. See the CI/CD documentation for the details.

Configuration

export STRIX_LLM="openrouter/z-ai/glm-5.3"
export LLM_API_KEY="your-api-key"

# Optional
export LLM_API_BASE="your-api-base-url"  # if using a local model, e.g. Ollama, LMStudio

Note

Strix automatically saves your configuration to ~/.strix/cli-config.json, so you don't have to re-enter it on every run. See the configuration reference for every environment variable.

Sign in with a ChatGPT subscription

Instead of a metered API key, you can run Strix on your ChatGPT Plus/Pro subscription:

strix auth login chatgpt             # sign in with your ChatGPT account
export STRIX_LLM="chatgpt/gpt-5.4"   # chatgpt/<model> runs on the subscription
strix auth status                    # show the active sign-in, or logout to forget it
Use the managed platform: strix cloud

Run scans on app.strix.ai from the terminal, without Docker or an LLM key:

strix cloud login                                  # browser sign-in, one credential per install
strix cloud scans start --source . --yes --wait    # scan local code, approving the upload
strix cloud scans start --engagement-type live_test --domain-ids <uuid> --wait
strix cloud vulns list --severity critical

Every REST API operation has a matching strix cloud <resource> <verb> command. Run strix cloud to list the resources, and add help to a resource to list its verbs. Output is JSON when stdout is not a terminal or when you pass --json. Binary downloads are the exception: redirect the raw bytes, or combine --output FILE --json for download metadata.

See the cloud CLI documentation for scopes, workspaces, billing, and source-upload options.

Connect your own MCP servers

Strix can connect to Model Context Protocol (MCP) servers you list and expose their tools to the agent during a run. Create ~/.strix/mcp-servers.json with a JSON list of local stdio servers or remote http servers:

[
  {
    "name": "github",
    "transport": "http",
    "url": "https://api.githubcopilot.com/mcp/",
    "auth": { "kind": "bearer", "token": "your-token" },
    "allowed_tools": ["list_issues"]
  }
]

Each server's tools are namespaced by name, for example github_list_issues. See the MCP documentation for the full schema, tool filtering, and stdio servers.

Recommended models for best results:

See the LLM Providers documentation for all supported providers including Vertex AI, Bedrock, Azure, and local models.

Documentation

Full documentation is available at docs.strix.ai - including detailed guides for usage, CI/CD integrations, skills, and advanced configuration.

Contributing

We welcome contributions of code, docs, and new skills - check out our Contributing Guide to get started or open a pull request/issue.

Join Our Community

Have questions? Found a bug? Want to contribute? Join our Discord!

Support the Project

Love Strix? Give us a ⭐ on GitHub!

Acknowledgements

Strix builds on the incredible work of open-source projects like LiteLLM, Caido, Nuclei, Playwright, and Bubble Tea. Huge thanks to their maintainers!

Warning

Authorized use only. Strix actively tests the targets you point it at, so only run it against systems you own or have explicit, written permission to test, and stay within the agreed scope. Unauthorized testing is illegal in most jurisdictions. You alone are responsible for obtaining authorization and complying with the law. Strix is provided "as is" with no warranty or liability for misuse.

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

29 total
  1. v1.6.2v1.6.2Sep 5, 202618.9K downloads

    ## What's Changed * fix(agents): stop parents waiting on finished non-interactive children by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1241 * fix(cloud): print top-up instructions on 402 and guide oversize or ar… by @bearsyankees in https://github.com/usestrix/strix/pull/1242 * fix(viewer): show stopped run status by @kusonooyasumi in https://github.com/usestrix/strix/pull/1249 * feat(web_search): add Exa as a web search provider alongside Perplexity by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1270 * fix(cli): join the import warm-up before the engine imports, drop the orphan purge by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1273 * chore(telemetry): drop per-load skill_loaded beacons, send anonymous events by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1275 * docs: update README and CLI links by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1272 * feat(telemetry): classify error beacons by phase and exception class by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1276 * chore: release v1.6.2 by @devin-ai-integration[bot] in https

  2. v1.6.1v1.6.1Sep 2, 20262.8K downloads

    ## What's Changed * skills: reference new cloud cli by @bearsyankees in https://github.com/usestrix/strix/pull/1227 * MCP call errors no longer quarantine the connection by @yoni-at-strix in https://github.com/usestrix/strix/pull/1228 * fix(tui): run environment and model checks on the no-target start screen by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1232 * fix(ci): make the pre-commit mypy hook and the test suite pass on a fresh checkout by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1234 * fix(config): merge env into cli-config.json and invalidate the linked LLM connection on change by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1236 * feat(models): add GLM-5.3, Fable 5.1, Gemini 3.7 Flash to the recommended list and make openrouter/z-ai/glm-5.3 the top pick by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1235 * docs(readme): trim the strix cloud section to the essentials by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1237 * docs: trim crammed README sections and add cloud CLI and viewer docs pages by @devin-ai-integration[bot] in https://github.com/uses

  3. v1.6.0v1.6.0Sep 1, 20261.3K downloads

    ## What's Changed * Fix LiteLLM cost model resolution by @bearsyankees in https://github.com/usestrix/strix/pull/1069 * feat: place caller-provided files into the sandbox workspace (`extra_files`, `--workspace-file`) by @yoni-at-strix in https://github.com/usestrix/strix/pull/1085 * feat(reporting): contextual CVSS breakdown on dependency reports by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1091 * feat(reporting): require contextual CVSS and usage evidence on dependency reports by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1092 * handle resume tokens gracefully by @bearsyankees in https://github.com/usestrix/strix/pull/1097 * Add OWASP LLM Top 10 2026 skill coverage by @bearsyankees in https://github.com/usestrix/strix/pull/1115 * Add Azure and Entra security skill by @bearsyankees in https://github.com/usestrix/strix/pull/1119 * Add argument injection security skill by @bearsyankees in https://github.com/usestrix/strix/pull/1120 * Add ecosystem supply-chain security skills by @bearsyankees in https://github.com/usestrix/strix/pull/1121 * Add Hurl and Hypothesis security playbooks by @bearsyankees in https://github.com/usestrix/s

  4. v1.5.3v1.5.3Aug 10, 202623.6K downloads

    ## What's Changed * fix(llm): omit parallel_tool_calls on tool-less requests by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1029 * fix(container): reclaim abandoned browser sessions by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1034 * fix(container): keep the browser env alive where image ENV is dropped by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1035 * fix(container): write the browser profile as root by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1039 * fix(llm): send OpenRouter app attribution on the request itself by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1045 * chore: release v1.5.3 by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1046 **Full Changelog**: https://github.com/usestrix/strix/compare/v1.5.2...v1.5.3

  5. v1.5.2v1.5.2Aug 9, 20262.2K downloads

    ## What's Changed * docs(skills): clearer description by @bearsyankees in https://github.com/usestrix/strix/pull/1013 * fix(tui): make the mount prompt clickable, and skip the mount instead of abandoning the scan by @0xallam in https://github.com/usestrix/strix/pull/1015 * test(tui): correct the nudge the internal-turn test asserts by @0xallam in https://github.com/usestrix/strix/pull/1016 * fix(agents): let an agent wait on what it already said by @0xallam in https://github.com/usestrix/strix/pull/1020 * fix(todo): stop a todo plan failing on priority or duplicates by @0xallam in https://github.com/usestrix/strix/pull/1021 * fix(sessions): open a sqlite connection per operation, not per thread by @0xallam in https://github.com/usestrix/strix/pull/1022 * fix(runner): resume after a user interrupt instead of failing by @0xallam in https://github.com/usestrix/strix/pull/1023 * fix(tools): coerce an empty-string list/dict argument to an empty container by @0xallam in https://github.com/usestrix/strix/pull/1024 * fix(runner): settle child agents before closing sessions at wind-down by @0xallam in https://github.com/usestrix/strix/pull/1025 * chore: release v1.5.2 by @devin-ai-integrati

Code frequency

additions and deletions
+35.8K-35.8KWeek of 2025-09-28: +65 linesWeek of 2025-09-28: -0 linesWeek of 2025-10-05: +217 linesWeek of 2025-10-05: -18 linesWeek of 2025-10-12: +2,872 linesWeek of 2025-10-12: -1,646 linesWeek of 2025-10-19: +56 linesWeek of 2025-10-19: -23 linesWeek of 2025-10-26: +5,842 linesWeek of 2025-10-26: -5,203 linesWeek of 2025-11-02: +209 linesWeek of 2025-11-02: -84 linesWeek of 2025-11-09: +500 linesWeek of 2025-11-09: -361 linesWeek of 2025-11-16: +129 linesWeek of 2025-11-16: -67 linesWeek of 2025-11-23: +873 linesWeek of 2025-11-23: -108 linesWeek of 2025-11-30: +835 linesWeek of 2025-11-30: -479 linesWeek of 2025-12-07: +2,132 linesWeek of 2025-12-07: -460 linesWeek of 2025-12-14: +1,914 linesWeek of 2025-12-14: -323 linesWeek of 2025-12-21: +0 linesWeek of 2025-12-21: -0 linesWeek of 2025-12-28: +13 linesWeek of 2025-12-28: -9 linesWeek of 2026-01-04: +9,645 linesWeek of 2026-01-04: -6,743 linesWeek of 2026-01-11: +1,576 linesWeek of 2026-01-11: -1,469 linesWeek of 2026-01-18: +10,081 linesWeek of 2026-01-18: -7,055 linesWeek of 2026-01-25: +64 linesWeek of 2026-01-25: -141 linesWeek of 2026-02-01: +222 linesWeek of 2026-02-01: -73 linesWeek of 2026-02-08: +157 linesWeek of 2026-02-08: -155 linesWeek of 2026-02-15: +1,001 linesWeek of 2026-02-15: -555 linesWeek of 2026-02-22: +113 linesWeek of 2026-02-22: -46 linesWeek of 2026-03-01: +5 linesWeek of 2026-03-01: -14 linesWeek of 2026-03-08: +3,347 linesWeek of 2026-03-08: -222 linesWeek of 2026-03-15: +1,183 linesWeek of 2026-03-15: -91 linesWeek of 2026-03-22: +208 linesWeek of 2026-03-22: -214 linesWeek of 2026-03-29: +8,724 linesWeek of 2026-03-29: -9,025 linesWeek of 2026-04-05: +0 linesWeek of 2026-04-05: -0 linesWeek of 2026-04-12: +152 linesWeek of 2026-04-12: -34 linesWeek of 2026-04-19: +28,205 linesWeek of 2026-04-19: -35,815 linesWeek of 2026-04-26: +12,595 linesWeek of 2026-04-26: -16,532 linesWeek of 2026-05-03: +886 linesWeek of 2026-05-03: -279 linesWeek of 2026-05-10: +0 linesWeek of 2026-05-10: -0 linesWeek of 2026-05-17: +382 linesWeek of 2026-05-17: -10 linesWeek of 2026-05-24: +2,516 linesWeek of 2026-05-24: -1,279 linesWeek of 2026-05-31: +0 linesWeek of 2026-05-31: -0 linesWeek of 2026-06-07: +586 linesWeek of 2026-06-07: -353 linesWeek of 2026-06-14: +2 linesWeek of 2026-06-14: -0 linesWeek of 2026-06-21: +867 linesWeek of 2026-06-21: -46 linesWeek of 2026-06-28: +4,520 linesWeek of 2026-06-28: -1,124 linesWeek of 2026-07-05: +1,527 linesWeek of 2026-07-05: -87 linesWeek of 2026-07-12: +7,208 linesWeek of 2026-07-12: -3,283 linesWeek of 2026-07-19: +25,818 linesWeek of 2026-07-19: -5,909 linesWeek of 2026-07-26: +23,541 linesWeek of 2026-07-26: -16,529 linesWeek of 2026-08-02: +23,610 linesWeek of 2026-08-02: -8,949 linesWeek of 2026-08-09: +1,906 linesWeek of 2026-08-09: -102 linesWeek of 2026-08-16: +3,944 linesWeek of 2026-08-16: -451 linesWeek of 2026-08-23: +14,335 linesWeek of 2026-08-23: -3,229 linesWeek of 2026-08-30: +21,720 linesWeek of 2026-08-30: -1,838 linesWeek of 2026-09-06: +600 linesWeek of 2026-09-06: -111 linesWeek of 2026-09-13: +949 linesWeek of 2026-09-13: -707 linesWeek of 2026-09-20: +5,757 linesWeek of 2026-09-20: -826 linesSep 28, 2025Sep 20, 2026
+233.6K lines added, -132.1K removed over the last year.

Commits per week

last 52 weeks
640Week of 2025-09-28: 3 commitsWeek of 2025-10-05: 1 commitsWeek of 2025-10-12: 10 commitsWeek of 2025-10-19: 2 commitsWeek of 2025-10-26: 19 commitsWeek of 2025-11-02: 4 commitsWeek of 2025-11-09: 18 commitsWeek of 2025-11-16: 4 commitsWeek of 2025-11-23: 7 commitsWeek of 2025-11-30: 14 commitsWeek of 2025-12-07: 14 commitsWeek of 2025-12-14: 14 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 4 commitsWeek of 2026-01-04: 64 commitsWeek of 2026-01-11: 34 commitsWeek of 2026-01-18: 38 commitsWeek of 2026-01-25: 4 commitsWeek of 2026-02-01: 7 commitsWeek of 2026-02-08: 2 commitsWeek of 2026-02-15: 22 commitsWeek of 2026-02-22: 9 commitsWeek of 2026-03-01: 5 commitsWeek of 2026-03-08: 7 commitsWeek of 2026-03-15: 6 commitsWeek of 2026-03-22: 7 commitsWeek of 2026-03-29: 2 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 2 commitsWeek of 2026-04-19: 61 commitsWeek of 2026-04-26: 28 commitsWeek of 2026-05-03: 8 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 2 commitsWeek of 2026-05-24: 22 commitsWeek of 2026-05-31: 0 commitsWeek of 2026-06-07: 23 commitsWeek of 2026-06-14: 1 commitsWeek of 2026-06-21: 2 commitsWeek of 2026-06-28: 17 commitsWeek of 2026-07-05: 21 commitsWeek of 2026-07-12: 43 commitsWeek of 2026-07-19: 39 commitsWeek of 2026-07-26: 40 commitsWeek of 2026-08-02: 39 commitsWeek of 2026-08-09: 20 commitsWeek of 2026-08-16: 25 commitsWeek of 2026-08-23: 13 commitsWeek of 2026-08-30: 44 commitsWeek of 2026-09-06: 3 commitsWeek of 2026-09-13: 10 commitsWeek of 2026-09-20: 5 commitsSep 28, 2025Sep 20, 2026
789 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 8 commitsSun 1:00 — 7 commitsSun 2:00 — 6 commitsSun 3:00 — 1 commitsSun 4:00 — 2 commitsSun 5:00 — 2 commitsSun 6:00 — 1 commitsSun 7:00 — 5 commitsSun 8:00 — 0 commitsSun 9:00 — 6 commitsSun 10:00 — 2 commitsSun 11:00 — 4 commitsSun 12:00 — 10 commitsSun 13:00 — 0 commitsSun 14:00 — 7 commitsSun 15:00 — 10 commitsSun 16:00 — 9 commitsSun 17:00 — 7 commitsSun 18:00 — 4 commitsSun 19:00 — 6 commitsSun 20:00 — 11 commitsSun 21:00 — 6 commitsSun 22:00 — 6 commitsSun 23:00 — 5 commitsMon 0:00 — 8 commitsMon 1:00 — 6 commitsMon 2:00 — 5 commitsMon 3:00 — 4 commitsMon 4:00 — 3 commitsMon 5:00 — 1 commitsMon 6:00 — 2 commitsMon 7:00 — 6 commitsMon 8:00 — 1 commitsMon 9:00 — 8 commitsMon 10:00 — 5 commitsMon 11:00 — 6 commitsMon 12:00 — 4 commitsMon 13:00 — 6 commitsMon 14:00 — 5 commitsMon 15:00 — 5 commitsMon 16:00 — 10 commitsMon 17:00 — 7 commitsMon 18:00 — 15 commitsMon 19:00 — 7 commitsMon 20:00 — 3 commitsMon 21:00 — 9 commitsMon 22:00 — 6 commitsMon 23:00 — 10 commitsTue 0:00 — 2 commitsTue 1:00 — 2 commitsTue 2:00 — 4 commitsTue 3:00 — 5 commitsTue 4:00 — 3 commitsTue 5:00 — 0 commitsTue 6:00 — 2 commitsTue 7:00 — 1 commitsTue 8:00 — 2 commitsTue 9:00 — 4 commitsTue 10:00 — 4 commitsTue 11:00 — 2 commitsTue 12:00 — 6 commitsTue 13:00 — 2 commitsTue 14:00 — 11 commitsTue 15:00 — 5 commitsTue 16:00 — 5 commitsTue 17:00 — 4 commitsTue 18:00 — 5 commitsTue 19:00 — 3 commitsTue 20:00 — 10 commitsTue 21:00 — 4 commitsTue 22:00 — 3 commitsTue 23:00 — 4 commitsWed 0:00 — 1 commitsWed 1:00 — 4 commitsWed 2:00 — 1 commitsWed 3:00 — 0 commitsWed 4:00 — 0 commitsWed 5:00 — 1 commitsWed 6:00 — 1 commitsWed 7:00 — 1 commitsWed 8:00 — 3 commitsWed 9:00 — 3 commitsWed 10:00 — 3 commitsWed 11:00 — 11 commitsWed 12:00 — 5 commitsWed 13:00 — 6 commitsWed 14:00 — 8 commitsWed 15:00 — 8 commitsWed 16:00 — 7 commitsWed 17:00 — 3 commitsWed 18:00 — 9 commitsWed 19:00 — 10 commitsWed 20:00 — 6 commitsWed 21:00 — 3 commitsWed 22:00 — 5 commitsWed 23:00 — 2 commitsThu 0:00 — 5 commitsThu 1:00 — 7 commitsThu 2:00 — 0 commitsThu 3:00 — 0 commitsThu 4:00 — 2 commitsThu 5:00 — 2 commitsThu 6:00 — 0 commitsThu 7:00 — 2 commitsThu 8:00 — 0 commitsThu 9:00 — 2 commitsThu 10:00 — 2 commitsThu 11:00 — 10 commitsThu 12:00 — 4 commitsThu 13:00 — 8 commitsThu 14:00 — 6 commitsThu 15:00 — 6 commitsThu 16:00 — 6 commitsThu 17:00 — 8 commitsThu 18:00 — 7 commitsThu 19:00 — 4 commitsThu 20:00 — 6 commitsThu 21:00 — 0 commitsThu 22:00 — 2 commitsThu 23:00 — 4 commitsFri 0:00 — 7 commitsFri 1:00 — 2 commitsFri 2:00 — 5 commitsFri 3:00 — 1 commitsFri 4:00 — 2 commitsFri 5:00 — 2 commitsFri 6:00 — 4 commitsFri 7:00 — 3 commitsFri 8:00 — 4 commitsFri 9:00 — 5 commitsFri 10:00 — 4 commitsFri 11:00 — 3 commitsFri 12:00 — 3 commitsFri 13:00 — 11 commitsFri 14:00 — 2 commitsFri 15:00 — 6 commitsFri 16:00 — 7 commitsFri 17:00 — 5 commitsFri 18:00 — 12 commitsFri 19:00 — 3 commitsFri 20:00 — 6 commitsFri 21:00 — 9 commitsFri 22:00 — 0 commitsFri 23:00 — 8 commitsSat 0:00 — 10 commitsSat 1:00 — 7 commitsSat 2:00 — 4 commitsSat 3:00 — 2 commitsSat 4:00 — 1 commitsSat 5:00 — 4 commitsSat 6:00 — 0 commitsSat 7:00 — 1 commitsSat 8:00 — 3 commitsSat 9:00 — 3 commitsSat 10:00 — 2 commitsSat 11:00 — 8 commitsSat 12:00 — 9 commitsSat 13:00 — 6 commitsSat 14:00 — 12 commitsSat 15:00 — 11 commitsSat 16:00 — 9 commitsSat 17:00 — 8 commitsSat 18:00 — 9 commitsSat 19:00 — 7 commitsSat 20:00 — 2 commitsSat 21:00 — 8 commitsSat 22:00 — 11 commitsSat 23:00 — 9 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Aug 19, 2026daily#2+598
Aug 18, 2026daily#2+598
Aug 7, 2026monthly#17+12,507
Aug 6, 2026monthly#17+12,507
Aug 5, 2026monthly#18+12,737
Aug 4, 2026monthly#15+13,453
Aug 3, 2026monthly#11+16,165
Aug 2, 2026monthly#8+17,847
Aug 1, 2026monthly#5+18,958
Jul 31, 2026monthly#3+19,044
Jul 30, 2026monthly#2+18,792
Jul 29, 2026monthly#2+19,164
Jul 28, 2026monthly#1+18,948
Jul 27, 2026monthly#1+18,515
Jul 19, 2026daily#22+5