Verdict. The right shape for a security pass before launch. Every finding comes with a working proof of concept, so it either reproduces or it doesn’t. That beats a static-analysis report full of maybes.
what it is
An open-source penetration-testing agent. It runs your application, finds vulnerabilities, and validates each one with a working exploit.
A team of recon, exploitation and post-exploitation agents works inside a Docker sandbox with a real offensive toolkit. That includes the Caido HTTP proxy, an automated browser for XSS, CSRF and auth bypass, an interactive shell, a Python exploit runtime, Nuclei and Playwright, plus SAST and DAST.
strix --target ./app-directoryThe target can also be a URL, a GitHub repo, an OpenAPI file or a Postman collection. -n runs it headless for CI. strix view opens a local dashboard. Nine agent skills install with npx skills add usestrix/strix.
Results go to strix_runs/<run-name>. You get validated findings with CVSS scores and OWASP classes, optional remediation patches, and a non-zero exit code when it finds something, so it drops straight into CI.
what I found
| Stars | 57,416 (6,220 forks), GitHub API, 2026-08-23 |
| License | Apache-2.0 |
| Commits | 100 in three weeks, 68 contributors |
| Tests | 73 pytest files |
| Release | v1.5.3 (2026-08-10) |
| Stack | Python core, Go TUI, TypeScript viewer. PyPI strix-agent |
- It needs Docker running and an LLM API key. It can also sign in with a ChatGPT Plus or Pro subscription (
strix auth login chatgpt). - Reasoning effort defaults to
high. Usemediumfor quick scans and budget for it. - It’s open-core. The CLI is free, and a paid platform adds SSO, compliance reporting and self-hosted deployment.
- Only one CI workflow, so test enforcement seems to lean on pre-commit hooks rather than PR gates.
strix viewbinds to127.0.0.1on a random port behind a tokened URL. It reads run files off disk and uploads nothing. You can steer a running scan by sending it new instructions mid-run.- The README says to only run it against systems you own or have written permission to test.