usestrix/strixPublic

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

AI summary: Open-source AI penetration testing tool that autonomously finds and fixes vulnerabilities.

Stars
49.4K
+177 today
Forks
5.3K
Watchers
223
Open issues
107
Open PRs
123
Contributors
~64
Commits
631
Branches
40

PythonApache-2.0Created Aug 5, 2025Last push todayLatest release v1.3.1+3.2K stars this week+4.5K this month

Star history

since Aug 10, 2025
020K40KAug 2025Dec 2025Apr 2026Aug 2026
49.4K stars as of Aug 7, 2026, tracked back to Aug 10, 2025. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulMonWedFri2025-08-03: 0 commits2025-08-04: 0 commits2025-08-05: 0 commits2025-08-06: 0 commits2025-08-07: 0 commits2025-08-08: 1 commit2025-08-09: 0 commits2025-08-10: 0 commits2025-08-11: 2 commits2025-08-12: 1 commit2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 1 commit2025-08-16: 2 commits2025-08-17: 0 commits2025-08-18: 2 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 1 commit2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 4 commits2025-09-09: 2 commits2025-09-10: 1 commit2025-09-11: 0 commits2025-09-12: 1 commit2025-09-13: 0 commits2025-09-14: 1 commit2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 2 commits2025-09-24: 3 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 2 commits2025-09-29: 1 commit2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 1 commit2025-10-11: 0 commits2025-10-12: 1 commit2025-10-13: 3 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 6 commits2025-10-19: 0 commits2025-10-20: 2 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 4 commits2025-10-30: 2 commits2025-10-31: 6 commits2025-11-01: 7 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 2 commits2025-11-06: 0 commits2025-11-07: 1 commit2025-11-08: 1 commit2025-11-09: 0 commits2025-11-10: 2 commits2025-11-11: 0 commits2025-11-12: 5 commits2025-11-13: 2 commits2025-11-14: 4 commits2025-11-15: 5 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 1 commit2025-11-22: 3 commits2025-11-23: 2 commits2025-11-24: 1 commit2025-11-25: 3 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 1 commit2025-11-30: 0 commits2025-12-01: 2 commits2025-12-02: 2 commits2025-12-03: 5 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 5 commits2025-12-07: 7 commits2025-12-08: 1 commit2025-12-09: 2 commits2025-12-10: 0 commits2025-12-11: 1 commit2025-12-12: 2 commits2025-12-13: 1 commit2025-12-14: 6 commits2025-12-15: 6 commits2025-12-16: 2 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 1 commit2026-01-02: 0 commits2026-01-03: 3 commits2026-01-04: 2 commits2026-01-05: 8 commits2026-01-06: 9 commits2026-01-07: 7 commits2026-01-08: 13 commits2026-01-09: 14 commits2026-01-10: 11 commits2026-01-11: 1 commit2026-01-12: 1 commit2026-01-13: 3 commits2026-01-14: 9 commits2026-01-15: 6 commits2026-01-16: 11 commits2026-01-17: 3 commits2026-01-18: 4 commits2026-01-19: 12 commits2026-01-20: 7 commits2026-01-21: 5 commits2026-01-22: 3 commits2026-01-23: 7 commits2026-01-24: 0 commits2026-01-25: 1 commit2026-01-26: 0 commits2026-01-27: 1 commit2026-01-28: 1 commit2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 1 commit2026-02-01: 3 commits2026-02-02: 0 commits2026-02-03: 1 commit2026-02-04: 1 commit2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 2 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 2 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 2 commits2026-02-16: 0 commits2026-02-17: 2 commits2026-02-18: 0 commits2026-02-19: 7 commits2026-02-20: 10 commits2026-02-21: 1 commit2026-02-22: 4 commits2026-02-23: 3 commits2026-02-24: 0 commits2026-02-25: 1 commit2026-02-26: 1 commit2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 3 commits2026-03-03: 2 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 2 commits2026-03-09: 1 commit2026-03-10: 0 commits2026-03-11: 2 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 2 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 1 commit2026-03-18: 0 commits2026-03-19: 5 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 7 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 2 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 1 commit2026-04-13: 1 commit2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 0 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 2 commits2026-04-23: 2 commits2026-04-24: 3 commits2026-04-25: 54 commits2026-04-26: 27 commits2026-04-27: 1 commit2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 3 commits2026-05-04: 5 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 1 commit2026-05-20: 0 commits2026-05-21: 1 commit2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 3 commits2026-05-25: 14 commits2026-05-26: 4 commits2026-05-27: 0 commits2026-05-28: 1 commit2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 6 commits2026-06-08: 13 commits2026-06-09: 4 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 0 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 1 commit2026-06-17: 0 commits2026-06-18: 0 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 2 commits2026-06-23: 0 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 5 commits2026-06-30: 2 commits2026-07-01: 0 commits2026-07-02: 2 commits2026-07-03: 6 commits2026-07-04: 2 commits2026-07-05: 0 commits2026-07-06: 6 commits2026-07-07: 4 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 10 commits2026-07-11: 1 commit2026-07-12: 7 commits2026-07-13: 7 commits2026-07-14: 4 commits2026-07-15: 2 commits2026-07-16: 14 commits2026-07-17: 5 commits2026-07-18: 4 commits2026-07-19: 1 commit2026-07-20: 4 commits2026-07-21: 6 commits2026-07-22: 11 commits2026-07-23: 0 commits2026-07-24: 4 commits2026-07-25: 13 commits2026-07-26: 11 commits2026-07-27: 1 commit2026-07-28: 0 commits2026-07-29: 0 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits
626 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    49,439 stars

  • Rising fast

    +3,237 stars this week

  • Very active

    626 commits in 52 weeks

  • Permissive license

    Apache-2.0

  • Continuous integration

    Automated checks passing

  • Repeat trending

    22 trending appearances

What strix does

Strix replaces manual penetration testing by deploying autonomous AI agents to analyze and exploit applications dynamically. It goes beyond static analysis by generating working proof-of-concept exploits to validate vulnerabilities, eliminating false positives. The platform provides actionable remediation steps tailored for developers, directly in the terminal or CI/CD logs. By supporting multi-agent orchestration, it scales distributed testing for complex attack scenarios. It integrates seamlessly into GitHub Actions to block insecure code before it reaches production.

Designed for developers, security teams, and ethical hackers aiming to automate and scale penetration testing. Requires familiarity with penetration testing concepts, Docker, and an active LLM API key.

  • Autonomous Agents: Deploys AI-driven bots for continuous reconnaissance, exploitation, and vulnerability validation.
  • Real Exploit Generation: Automatically crafts working proof-of-concept exploits to confirm findings.
  • Terminal-Native Developer UX: Surfaces actionable findings and clear remediation guidance directly in the CLI.
  • Distributed Testing Orchestration: Coordinates multiple agents to execute sophisticated attack chains and distributed testing.
  • Seamless CI/CD Integration: Embeds natively into GitHub Actions to fail builds upon detecting critical vulnerabilities.

Where teams use it

Continuous Security Testing

Security teams automate scanning for critical vulnerabilities, receiving validated findings and exact remediation steps without manual verification overhead.

Automated Bug Bounty Research

Ethical hackers deploy Strix to accelerate vulnerability discovery and automate the creation of proof-of-concept exploits for faster reporting.

Secure CI/CD Pipelines

DevOps teams integrate Strix workflows into their CI pipelines to automatically block pull requests introducing exploitable vulnerabilities.

Compliance Penetration Testing

Organizations rapidly perform and document comprehensive penetration tests in hours to satisfy compliance and audit requirements.

Getting started: curl -sSL https://strix.ai/install | curl && strix --target ./app-directory

README

main branch

Strix Banner

Strix

The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities.


Docs Website

Ask DeepWiki GitHub Stars License PyPI Version

Join Discord Follow on X

usestrix%2Fstrix | Trendshift usestrix/strix | Trendshift

Tip

New! Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - Get started with no setup required.


Strix Overview

Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.

Key Capabilities:

  • Full pentesting toolkit - reconnaissance, exploitation, and validation out of the box
  • Multi-agent orchestration - teams of AI pentesters that collaborate and scale
  • Real exploit validation - working PoCs, not false positives like legacy vulnerability scanners
  • Developer‑first CLI - actionable findings with remediation guidance
  • Auto‑fix & reporting - generate patches and compliance-ready pentest reports

Use Cases

  • Application Security Testing - Detect and validate critical vulnerabilities in your applications
  • Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports
  • Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting
  • CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production

🚀 Quick Start

Prerequisites:

  • Docker (running)
  • An LLM API key from any supported provider (OpenAI, Anthropic, Google, etc.)

Installation & First Scan

# Install Strix
curl -sSL https://strix.ai/install | bash

# Configure your AI provider
export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"

# Run your first security assessment
strix --target ./app-directory

Note

First run automatically pulls the sandbox Docker image. Results are saved to strix_runs/<run-name>


☁️ Strix Platform

Try the Strix full-stack penetration testing platform at app.strix.ai - sign up for free, connect your repos and domains, and launch a pentest in minutes.

  • Validated findings with PoCs - every vulnerability includes a working proof-of-concept exploit and reproduction steps
  • One-click autofix - AI-generated security patches as ready-to-merge pull requests
  • Continuous pentesting - always-on vulnerability scanning that keeps pace with your deployments
  • DevSecOps integrations - GitHub, GitLab, Bitbucket, Slack, Jira, Linear, and CI/CD pipelines
  • Continuous learning - AI that builds on past findings, adapts to your codebase, and reduces false positives over time

Start your first pentest →


✨ Features

Agentic Pentesting Tools

Strix agents come equipped with a comprehensive offensive security toolkit - the same tools used by professional penetration testers and ethical hackers:

  • HTTP Interception Proxy - Full request/response manipulation and analysis with Caido
  • Browser Exploitation - Automated browser for testing XSS, CSRF, clickjacking, and auth bypass flows
  • Shell & Command Execution - Interactive terminal for exploit development and post-exploitation
  • Custom Exploit Runtime - Python sandbox for writing and validating proof-of-concept exploits
  • Reconnaissance & OSINT - Automated attack surface mapping, subdomain enumeration, and fingerprinting
  • Static & Dynamic Code Analysis - SAST + DAST capabilities for comprehensive application security testing
  • Vulnerability Knowledge Base - Structured findings with CVSS scoring and OWASP classification

Comprehensive Vulnerability Scanner

Strix identifies, validates, and exploits a wide range of security vulnerabilities across the OWASP Top 10 and beyond:

  • Broken Access Control - IDOR, privilege escalation, auth bypass
  • Injection Attacks - SQL injection, NoSQL injection, OS command injection, SSTI
  • Server-Side Vulnerabilities - SSRF, XXE, insecure deserialization, RCE
  • Client-Side Attacks - XSS (stored/reflected/DOM), prototype pollution, CSRF
  • Business Logic Flaws - Race conditions, payment manipulation, workflow bypass
  • Authentication & Session - JWT attacks, session fixation, credential stuffing vectors
  • Infrastructure & Cloud - Misconfigurations, exposed services, cloud security issues
  • API Security - Broken authentication, mass assignment, rate limiting bypass

Graph of Agents (Multi-Agent Pentesting)

Advanced multi-agent orchestration for comprehensive automated penetration testing:

  • Distributed Pentesting - Specialized AI agents for recon, exploitation, and post-exploitation
  • Scalable Security Testing - Parallel execution across multiple targets for fast, comprehensive coverage
  • Dynamic Coordination - Agents share discoveries, chain vulnerabilities, and collaborate like a red team

🖥️ Local Web Viewer

Every scan writes its results to disk as it runs. Bring them up in a local dashboard with a single command:

# Open the most recent run
strix view

# ...or open a specific run by name
strix view my-run-name

strix view starts a lightweight local server (bound to 127.0.0.1 on a random port) and opens your browser to a private, tokened link. Nothing leaves your machine: the dashboard reads the run's files straight off disk, with no cloud account or upload required. The UI ships prebuilt with Strix, so there is no extra install and no JS build step.

What's in the dashboard

  • Overview: run status, target, and a severity breakdown of everything found so far.
  • Vulnerabilities: each validated finding with its severity, details, and reproduction steps.
  • Agent graph: a live map of the multi-agent team, showing which agent is doing what.
  • Steering: send instructions to a live scan from the browser to redirect the agents mid-run.
  • History: browse past runs on this machine and jump between them.
  • Reports: generate a shareable report and email it to yourself or your team.

Usage Examples

Basic Usage

# Scan a local codebase
strix --target ./app-directory

# Security review of a GitHub repository
strix --target https://github.com/org/repo

# Black-box web application assessment
strix --target https://your-app.com

Advanced Testing Scenarios

# Grey-box authenticated testing
strix --target https://your-app.com --instruction "Perform authenticated testing using credentials: user:pass"

# Multi-target testing (source code + deployed app)
strix -t https://github.com/org/app -t https://your-app.com

# Targets from a file, one target per non-empty, non-comment line
strix --target-list ./targets.txt

# White-box source-aware scan (local repository)
strix --target ./app-directory --scan-mode standard

# Focused testing with custom instructions
strix --target api.your-app.com --instruction "Focus on business logic flaws and IDOR vulnerabilities"

# Provide detailed instructions through file (e.g., rules of engagement, scope, exclusions)
strix --target api.your-app.com --instruction-file ./instruction.md

# Force PR diff-scope against a specific base branch
strix -n --target ./ --scan-mode quick --scope-mode diff --diff-base origin/main

Headless Mode

Run Strix programmatically without interactive UI using the -n/--non-interactive flag - perfect for servers and automated jobs. The CLI prints real-time vulnerability findings and the final report before exiting. Exits with non-zero code when vulnerabilities are found.

strix -n --target https://your-app.com

CI/CD (GitHub Actions)

Strix can be added to your pipeline to run a security test on pull requests with a lightweight GitHub Actions workflow:

name: strix-penetration-test

on:
  pull_request:

jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
        with:
          fetch-depth: 0

      - name: Install Strix
        run: curl -sSL https://strix.ai/install | bash

      - name: Run Strix
        env:
          STRIX_LLM: ${{ secrets.STRIX_LLM }}
          LLM_API_KEY: ${{ secrets.LLM_API_KEY }}

        run: strix -n -t ./ --scan-mode quick

Tip

In CI pull request runs, Strix automatically scopes quick reviews to changed files. If diff-scope cannot resolve, ensure checkout uses full history (fetch-depth: 0) or pass --diff-base explicitly.

Configuration

export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"

# Optional
export LLM_API_BASE="your-api-base-url"  # if using a local model, e.g. Ollama, LMStudio
export PERPLEXITY_API_KEY="your-api-key"  # for search capabilities
export STRIX_REASONING_EFFORT="high"  # control thinking effort (default: high, quick scan: medium)

Note

Strix automatically saves your configuration to ~/.strix/cli-config.json, so you don't have to re-enter it on every run.

Sign in with a ChatGPT subscription

Instead of a metered API key, you can run Strix on your ChatGPT Plus/Pro subscription:

strix auth login chatgpt      # sign in with your ChatGPT account

export STRIX_LLM="chatgpt/gpt-5.4"   # chatgpt/<model> runs on the subscription
strix --target ./app-directory

strix auth status             # show the active sign-in
strix auth logout             # forget the sign-in

Recommended models for best results:

See the LLM Providers documentation for all supported providers including Vertex AI, Bedrock, Azure, and local models.

Enterprise Pentesting

Get the same Strix experience with enterprise-grade controls: SSO (SAML/OIDC), custom compliance-ready penetration testing reports (SOC 2, ISO 27001, PCI DSS), dedicated support & SLA, custom deployment options (VPC/self-hosted), BYOK model support, and tailored AI pentesting agents optimized for your environment. Learn more.

Documentation

Full documentation is available at docs.strix.ai - including detailed guides for usage, CI/CD integrations, skills, and advanced configuration.

Contributing

We welcome contributions of code, docs, and new skills - check out our Contributing Guide to get started or open a pull request/issue.

Join Our Community

Have questions? Found a bug? Want to contribute? Join our Discord!

Support the Project

Love Strix? Give us a ⭐ on GitHub!

Acknowledgements

Strix builds on the incredible work of open-source projects like LiteLLM, Caido, Nuclei, Playwright, and Textual. Huge thanks to their maintainers!

Warning

Only test apps you own or have permission to test. You are responsible for using Strix ethically and legally.

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

20 total
  1. v1.3.1v1.3.1Jul 22, 20262.2K downloads

    ## What's Changed * sandbox: bump default inner-sandbox image to 1.1.0 by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/850 * chore: release v1.3.1 by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/853 **Full Changelog**: https://github.com/usestrix/strix/compare/v1.3.0...v1.3.1

  2. v1.3.0v1.3.0Jul 22, 202681 downloads

    ## What's Changed * fix(container): keep /app/.venv/bin on the login-shell PATH so python… by @bearsyankees in https://github.com/usestrix/strix/pull/839 * fix(prompt): make root agent orchestrate-only and fold fixing into reporting by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/827 * sandbox: shrink image 7.2GB → 3.8GB (cache cleanup, multi-stage Go build, drop ZAP) by @seanturner83 in https://github.com/usestrix/strix/pull/474 * Local viewer: UI polish and a Feedback & support tab by @0xallam in https://github.com/usestrix/strix/pull/847 * Local viewer: prominent scan switcher + rename to "pentest" terminology by @0xallam in https://github.com/usestrix/strix/pull/848 * chore: release v1.3.0 by @0xallam in https://github.com/usestrix/strix/pull/849 **Full Changelog**: https://github.com/usestrix/strix/compare/v1.2.0...v1.3.0

  3. v1.2.0v1.2.0Jul 21, 2026599 downloads

    ## What's Changed * fix(runtime): stage symlink-safe copies for LocalDir uploads by @bearsyankees in https://github.com/usestrix/strix/pull/766 * fix(runtime): retry transient sandbox startup failures by @bearsyankees in https://github.com/usestrix/strix/pull/768 * feat(runtime): resolve sandbox ports over a shared Docker network by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/775 * fix(core): bound per-agent image memory (proactive budget + inherited-context scrub) by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/779 * feat(runtime): opt-in resource limits for docker sandbox containers by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/780 * Revert "fix(runtime): retry transient sandbox startup failures (#768)" by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/782 * docs(prompts,skills): bound recon output for shared-disk hygiene by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/783 * docs(tools): guide proportional wait_for_message timeouts by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/784 * docs(prompts,skills): stop hardcoding /workspace/scra

  4. v1.1.0v1.1.0Jul 14, 20264.6K downloads

    # Strix v1.1.0 First release since v1.0.4. Highlights below (~56 merged PRs). ## New security skills - Weak-password detection skill (#621, #654) - LLM prompt-injection skill (#616) - GCP and Auth0 reconnaissance skills - Five new skills: OAuth, AWS, prototype pollution, deserialization, Django (#617) - Skill-directory registration (#746) ## SARIF / CI integration - SARIF 2.1.0 emitter for GitHub code-scanning / ASPM ingestion (#626) - STRIDE tagging of SARIF rules derived from CWE (#708) - Omit SARIF version-control provenance for multi-repo scans (#726) ## Dependency / SCA reporting - New dependency reporting fields (#751) - Require `advisory_cvss` for dependency findings + SCA TUI renderer (#753) ## Cost & scope controls - Configurable token / cost usage limits, `--max-budget-usd` (#576) - Bind-mount option for large target repos (#577) - `--target` list-file CLI option (#711) ## LLM / provider - Use core LiteLLM dependency (#752); cap `openai<2.45` + `litellm[proxy]` so fresh installs run (#748) - `force_required_tool_choice` setting (#730) and routed OpenAI required tool choice (#732) - Scan-agent tool registration (#733); root scan prompt options (#750) - Attribute Open

  5. v1.0.4v1.0.4Jun 9, 202611.6K downloads

    ## What's Changed * Make TUI quit instant by SIGKILL-ing the sandbox container by @0xallam in https://github.com/usestrix/strix/pull/548 * Swallow sandbox container races in the stream consumer by @0xallam in https://github.com/usestrix/strix/pull/552 * Strip all images from session on vision-rejection, not just the latest by @0xallam in https://github.com/usestrix/strix/pull/553 * Strip ANSI escapes and control bytes from terminal tool output by @0xallam in https://github.com/usestrix/strix/pull/554 * Bump 1.0.3 -> 1.0.4 by @0xallam in https://github.com/usestrix/strix/pull/557 **Full Changelog**: https://github.com/usestrix/strix/compare/v1.0.3...v1.0.4

Code frequency

additions and deletions
+35.8K-35.8KWeek of 2025-08-03: +22,125 linesWeek of 2025-08-03: -0 linesWeek of 2025-08-10: +1,778 linesWeek of 2025-08-10: -1,638 linesWeek of 2025-08-17: +762 linesWeek of 2025-08-17: -479 linesWeek of 2025-08-24: +0 linesWeek of 2025-08-24: -0 linesWeek of 2025-08-31: +0 linesWeek of 2025-08-31: -13 linesWeek of 2025-09-07: +222 linesWeek of 2025-09-07: -204 linesWeek of 2025-09-14: +100 linesWeek of 2025-09-14: -11 linesWeek of 2025-09-21: +185 linesWeek of 2025-09-21: -90 linesWeek of 2025-09-28: +65 linesWeek of 2025-09-28: -0 linesWeek of 2025-10-05: +217 linesWeek of 2025-10-05: -18 linesWeek of 2025-10-12: +2,872 linesWeek of 2025-10-12: -1,646 linesWeek of 2025-10-19: +56 linesWeek of 2025-10-19: -23 linesWeek of 2025-10-26: +5,842 linesWeek of 2025-10-26: -5,203 linesWeek of 2025-11-02: +209 linesWeek of 2025-11-02: -84 linesWeek of 2025-11-09: +500 linesWeek of 2025-11-09: -361 linesWeek of 2025-11-16: +129 linesWeek of 2025-11-16: -67 linesWeek of 2025-11-23: +873 linesWeek of 2025-11-23: -108 linesWeek of 2025-11-30: +835 linesWeek of 2025-11-30: -479 linesWeek of 2025-12-07: +2,132 linesWeek of 2025-12-07: -460 linesWeek of 2025-12-14: +1,914 linesWeek of 2025-12-14: -323 linesWeek of 2025-12-21: +0 linesWeek of 2025-12-21: -0 linesWeek of 2025-12-28: +13 linesWeek of 2025-12-28: -9 linesWeek of 2026-01-04: +9,645 linesWeek of 2026-01-04: -6,743 linesWeek of 2026-01-11: +1,576 linesWeek of 2026-01-11: -1,469 linesWeek of 2026-01-18: +10,081 linesWeek of 2026-01-18: -7,055 linesWeek of 2026-01-25: +64 linesWeek of 2026-01-25: -141 linesWeek of 2026-02-01: +222 linesWeek of 2026-02-01: -73 linesWeek of 2026-02-08: +157 linesWeek of 2026-02-08: -155 linesWeek of 2026-02-15: +1,001 linesWeek of 2026-02-15: -555 linesWeek of 2026-02-22: +113 linesWeek of 2026-02-22: -46 linesWeek of 2026-03-01: +5 linesWeek of 2026-03-01: -14 linesWeek of 2026-03-08: +3,347 linesWeek of 2026-03-08: -222 linesWeek of 2026-03-15: +1,183 linesWeek of 2026-03-15: -91 linesWeek of 2026-03-22: +208 linesWeek of 2026-03-22: -214 linesWeek of 2026-03-29: +8,724 linesWeek of 2026-03-29: -9,025 linesWeek of 2026-04-05: +0 linesWeek of 2026-04-05: -0 linesWeek of 2026-04-12: +152 linesWeek of 2026-04-12: -34 linesWeek of 2026-04-19: +28,205 linesWeek of 2026-04-19: -35,815 linesWeek of 2026-04-26: +12,595 linesWeek of 2026-04-26: -16,532 linesWeek of 2026-05-03: +886 linesWeek of 2026-05-03: -279 linesWeek of 2026-05-10: +0 linesWeek of 2026-05-10: -0 linesWeek of 2026-05-17: +382 linesWeek of 2026-05-17: -10 linesWeek of 2026-05-24: +2,516 linesWeek of 2026-05-24: -1,279 linesWeek of 2026-05-31: +0 linesWeek of 2026-05-31: -0 linesWeek of 2026-06-07: +586 linesWeek of 2026-06-07: -353 linesWeek of 2026-06-14: +2 linesWeek of 2026-06-14: -0 linesWeek of 2026-06-21: +867 linesWeek of 2026-06-21: -46 linesWeek of 2026-06-28: +4,520 linesWeek of 2026-06-28: -1,124 linesWeek of 2026-07-05: +1,527 linesWeek of 2026-07-05: -87 linesWeek of 2026-07-12: +7,208 linesWeek of 2026-07-12: -3,283 linesWeek of 2026-07-19: +25,818 linesWeek of 2026-07-19: -5,909 linesWeek of 2026-07-26: +19,751 linesWeek of 2026-07-26: -15,535 linesAug 3, 2025Jul 26, 2026
+182.2K lines added, -117.3K removed over the last year.

Commits per week

last 52 weeks
640Week of 2025-08-03: 1 commitsWeek of 2025-08-10: 6 commitsWeek of 2025-08-17: 2 commitsWeek of 2025-08-24: 0 commitsWeek of 2025-08-31: 1 commitsWeek of 2025-09-07: 8 commitsWeek of 2025-09-14: 1 commitsWeek of 2025-09-21: 5 commitsWeek of 2025-09-28: 3 commitsWeek of 2025-10-05: 1 commitsWeek of 2025-10-12: 10 commitsWeek of 2025-10-19: 2 commitsWeek of 2025-10-26: 19 commitsWeek of 2025-11-02: 4 commitsWeek of 2025-11-09: 18 commitsWeek of 2025-11-16: 4 commitsWeek of 2025-11-23: 7 commitsWeek of 2025-11-30: 14 commitsWeek of 2025-12-07: 14 commitsWeek of 2025-12-14: 14 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 4 commitsWeek of 2026-01-04: 64 commitsWeek of 2026-01-11: 34 commitsWeek of 2026-01-18: 38 commitsWeek of 2026-01-25: 4 commitsWeek of 2026-02-01: 7 commitsWeek of 2026-02-08: 2 commitsWeek of 2026-02-15: 22 commitsWeek of 2026-02-22: 9 commitsWeek of 2026-03-01: 5 commitsWeek of 2026-03-08: 7 commitsWeek of 2026-03-15: 6 commitsWeek of 2026-03-22: 7 commitsWeek of 2026-03-29: 2 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 2 commitsWeek of 2026-04-19: 61 commitsWeek of 2026-04-26: 28 commitsWeek of 2026-05-03: 8 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 2 commitsWeek of 2026-05-24: 22 commitsWeek of 2026-05-31: 0 commitsWeek of 2026-06-07: 23 commitsWeek of 2026-06-14: 1 commitsWeek of 2026-06-21: 2 commitsWeek of 2026-06-28: 17 commitsWeek of 2026-07-05: 21 commitsWeek of 2026-07-12: 43 commitsWeek of 2026-07-19: 39 commitsWeek of 2026-07-26: 12 commitsAug 3, 2025Jul 26, 2026
626 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 7 commitsSun 1:00 — 5 commitsSun 2:00 — 2 commitsSun 3:00 — 0 commitsSun 4:00 — 1 commitsSun 5:00 — 2 commitsSun 6:00 — 0 commitsSun 7:00 — 4 commitsSun 8:00 — 0 commitsSun 9:00 — 6 commitsSun 10:00 — 2 commitsSun 11:00 — 3 commitsSun 12:00 — 6 commitsSun 13:00 — 0 commitsSun 14:00 — 7 commitsSun 15:00 — 10 commitsSun 16:00 — 7 commitsSun 17:00 — 7 commitsSun 18:00 — 4 commitsSun 19:00 — 6 commitsSun 20:00 — 11 commitsSun 21:00 — 5 commitsSun 22:00 — 6 commitsSun 23:00 — 4 commitsMon 0:00 — 7 commitsMon 1:00 — 6 commitsMon 2:00 — 5 commitsMon 3:00 — 3 commitsMon 4:00 — 3 commitsMon 5:00 — 1 commitsMon 6:00 — 1 commitsMon 7:00 — 5 commitsMon 8:00 — 1 commitsMon 9:00 — 2 commitsMon 10:00 — 5 commitsMon 11:00 — 1 commitsMon 12:00 — 4 commitsMon 13:00 — 6 commitsMon 14:00 — 5 commitsMon 15:00 — 4 commitsMon 16:00 — 8 commitsMon 17:00 — 7 commitsMon 18:00 — 10 commitsMon 19:00 — 6 commitsMon 20:00 — 1 commitsMon 21:00 — 8 commitsMon 22:00 — 5 commitsMon 23:00 — 10 commitsTue 0:00 — 2 commitsTue 1:00 — 2 commitsTue 2:00 — 2 commitsTue 3:00 — 3 commitsTue 4:00 — 3 commitsTue 5:00 — 0 commitsTue 6:00 — 2 commitsTue 7:00 — 1 commitsTue 8:00 — 0 commitsTue 9:00 — 3 commitsTue 10:00 — 4 commitsTue 11:00 — 2 commitsTue 12:00 — 5 commitsTue 13:00 — 1 commitsTue 14:00 — 7 commitsTue 15:00 — 3 commitsTue 16:00 — 4 commitsTue 17:00 — 3 commitsTue 18:00 — 2 commitsTue 19:00 — 2 commitsTue 20:00 — 8 commitsTue 21:00 — 3 commitsTue 22:00 — 3 commitsTue 23:00 — 3 commitsWed 0:00 — 1 commitsWed 1:00 — 4 commitsWed 2:00 — 1 commitsWed 3:00 — 0 commitsWed 4:00 — 0 commitsWed 5:00 — 1 commitsWed 6:00 — 1 commitsWed 7:00 — 0 commitsWed 8:00 — 2 commitsWed 9:00 — 3 commitsWed 10:00 — 2 commitsWed 11:00 — 4 commitsWed 12:00 — 1 commitsWed 13:00 — 2 commitsWed 14:00 — 3 commitsWed 15:00 — 5 commitsWed 16:00 — 6 commitsWed 17:00 — 2 commitsWed 18:00 — 7 commitsWed 19:00 — 7 commitsWed 20:00 — 5 commitsWed 21:00 — 3 commitsWed 22:00 — 1 commitsWed 23:00 — 2 commitsThu 0:00 — 0 commitsThu 1:00 — 5 commitsThu 2:00 — 0 commitsThu 3:00 — 0 commitsThu 4:00 — 1 commitsThu 5:00 — 0 commitsThu 6:00 — 0 commitsThu 7:00 — 2 commitsThu 8:00 — 0 commitsThu 9:00 — 1 commitsThu 10:00 — 2 commitsThu 11:00 — 10 commitsThu 12:00 — 1 commitsThu 13:00 — 5 commitsThu 14:00 — 3 commitsThu 15:00 — 6 commitsThu 16:00 — 5 commitsThu 17:00 — 8 commitsThu 18:00 — 3 commitsThu 19:00 — 2 commitsThu 20:00 — 2 commitsThu 21:00 — 0 commitsThu 22:00 — 2 commitsThu 23:00 — 3 commitsFri 0:00 — 6 commitsFri 1:00 — 2 commitsFri 2:00 — 3 commitsFri 3:00 — 1 commitsFri 4:00 — 2 commitsFri 5:00 — 2 commitsFri 6:00 — 4 commitsFri 7:00 — 3 commitsFri 8:00 — 4 commitsFri 9:00 — 3 commitsFri 10:00 — 2 commitsFri 11:00 — 3 commitsFri 12:00 — 2 commitsFri 13:00 — 9 commitsFri 14:00 — 1 commitsFri 15:00 — 3 commitsFri 16:00 — 5 commitsFri 17:00 — 3 commitsFri 18:00 — 6 commitsFri 19:00 — 3 commitsFri 20:00 — 6 commitsFri 21:00 — 8 commitsFri 22:00 — 0 commitsFri 23:00 — 7 commitsSat 0:00 — 7 commitsSat 1:00 — 5 commitsSat 2:00 — 4 commitsSat 3:00 — 2 commitsSat 4:00 — 1 commitsSat 5:00 — 4 commitsSat 6:00 — 0 commitsSat 7:00 — 1 commitsSat 8:00 — 3 commitsSat 9:00 — 3 commitsSat 10:00 — 2 commitsSat 11:00 — 7 commitsSat 12:00 — 9 commitsSat 13:00 — 6 commitsSat 14:00 — 12 commitsSat 15:00 — 11 commitsSat 16:00 — 8 commitsSat 17:00 — 7 commitsSat 18:00 — 8 commitsSat 19:00 — 5 commitsSat 20:00 — 2 commitsSat 21:00 — 5 commitsSat 22:00 — 7 commitsSat 23:00 — 9 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Aug 7, 2026monthly#17+12,507
Aug 6, 2026monthly#17+12,507
Aug 5, 2026monthly#18+12,737
Aug 4, 2026monthly#15+13,453
Aug 3, 2026monthly#11+16,165
Aug 2, 2026monthly#8+17,847
Aug 1, 2026monthly#5+18,958
Jul 31, 2026monthly#3+19,044
Jul 30, 2026monthly#2+18,792
Jul 29, 2026monthly#2+19,164
Jul 28, 2026monthly#1+18,948
Jul 27, 2026monthly#1+18,515
Jul 19, 2026daily#22+5
Jul 16, 2026daily#22+4
Jul 9, 2026daily#15+4