usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. observed · 2026-08-28
Health v2 · maintenance only
84/100
- Activity 99
- Release rhythm 97
- Longevity 28
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 3
- age_days: 393
- days_rel: 23
- days_push: 7
- n_releases_24m: 26
Adoption not part of the score
58564 stars · 6382 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. It performs dynamic testing with real proof-of-exploit evidence across web apps, APIs, code, and cloud infrastructure, and integrates with CI/CD pipelines for continuous security testing.
Use cases
- run automated penetration tests on my web app
- find exploitable vulnerabilities in my REST or GraphQL API with proof-of-concept
- scan pull requests for security issues before merging
- automate pentesting in my CI/CD pipeline
- test cloud and Kubernetes infrastructure for misconfigurations
- generate fix PRs for discovered vulnerabilities
- practice CTF and bug bounty hunting with AI agents
When to choose
- you need dynamic, exploit-validated security testing rather than static scanner noise
- you want continuous pentesting integrated into GitHub Actions or CI/CD
- you need multi-agent AI testing across web apps, APIs, code, and cloud infrastructure
- you want automated remediation with merge-ready fix PRs
When to avoid
- you need a passive static code scanner with zero execution of your app
- you cannot allow an autonomous agent to run exploits against your systems
- you need a fully offline tool with no LLM API dependency
- your compliance requires human-led manual penetration testing reports only
Facets
cli-tool · maturity active
penetration-testing security agent-framework vulnerability-scanning llm-inference developer-tools security penetration-testing artificial-intelligence developer-tools python cli cloud ai-pentesting autonomous-agents red-teaming bug-bounty ctf offensive-security security-automation proof-of-exploit ci-cd-integration auto-fix ai-agents devops linux macos docker
9 sources
- readme: https://github.com/usestrix/strix · fetched 2026-08-28 · 253bfbb0f03c
- homepage: https://strix.ai · fetched 2026-08-28 · d542776ff1fe
- site_page: https://docs.app.strix.ai · fetched 2026-08-28 · 90f862418238
- site_page: https://www.strix.ai/features/autonomous-pentesting · fetched 2026-08-28 · 7def2cd4768b
- site_page: https://www.strix.ai/features/pr-reviews · fetched 2026-08-28 · 7e87a8983b26
- site_page: https://www.strix.ai/features/auto-fix · fetched 2026-08-28 · bbf1a015148b
- site_page: https://www.strix.ai/features/continuous-coverage · fetched 2026-08-28 · 2b7bb768f59d
- site_page: https://www.strix.ai/features/infrastructure · fetched 2026-08-28 · 1fe92354a6b4
- site_page: https://www.strix.ai/pricing · fetched 2026-08-28 · 209a72b7b300
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| usestrix/strix | main | 84 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem