# Strix ### Open-source AI hackers for your apps [![Apache 2.0](https://img.shields.io/badge/license-Apache%202.0-blue.svg)](LICENSE) [![Vercel AI Accelerator 2025](https://img.shields.io/badge/Vercel%20AI-Accelerator%202025-000000?style=flat&logo=vercel)](https://vercel.com/ai-accelerator) [![Status: Alpha](https://img.shields.io/badge/status-alpha-orange.svg)](https://github.com/usestrix/strix)
Strix Demo
--- ## πŸ¦‰ Strix Overview Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual exploitation. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools. ### πŸš€ Quick Start ```bash # Install pipx install strix-agent # Configure AI provider export STRIX_LLM="openai/gpt-5" export LLM_API_KEY="your-api-key" # Run security assessment strix --target ./app-directory ``` ## Why Use Strix - **Full Hacker Arsenal** - All the tools a professional hacker needs, built into the agents - **Real Validation** - Dynamic testing and actual exploitation, thus much fewer false positives - **Developer-First** - Seamlessly integrates into existing development workflows - **Auto-Fix & Reporting** - Automated patching with detailed remediation and security reports ## ✨ Features ### πŸ› οΈ Agentic Security Tools - **πŸ”Œ Full HTTP Proxy** - Full request/response manipulation and analysis - **🌐 Browser Automation** - Multi-tab browser for testing of XSS, CSRF, auth flows - **πŸ’» Terminal Environments** - Interactive shells for command execution and testing - **🐍 Python Runtime** - Custom exploit development and validation - **πŸ” Reconnaissance** - Automated OSINT and attack surface mapping - **πŸ“ Code Analysis** - Static and dynamic analysis capabilities - **πŸ“ Knowledge Management** - Structured findings and attack documentation ### 🎯 Comprehensive Vulnerability Detection - **Access Control** - IDOR, privilege escalation, auth bypass - **Injection Attacks** - SQL, NoSQL, command injection - **Server-Side** - SSRF, XXE, deserialization flaws - **Client-Side** - XSS, prototype pollution, DOM vulnerabilities - **Business Logic** - Race conditions, workflow manipulation - **Authentication** - JWT vulnerabilities, session management - **Infrastructure** - Misconfigurations, exposed services ### πŸ•ΈοΈ Graph of Agents - **Distributed Workflows** - Specialized agents for different attacks and assets - **Scalable Testing** - Parallel execution for fast comprehensive coverage - **Dynamic Coordination** - Agents collaborate and share discoveries ## πŸ’» Usage Examples ```bash # Local codebase analysis strix --target ./app-directory # Repository security review strix --target https://github.com/org/repo # Web application assessment strix --target https://your-app.com # Focused testing strix --target api.your-app.com --instruction "Prioritize authentication and authorization testing" ``` ### βš™οΈ Configuration ```bash export STRIX_LLM="openai/gpt-5" export LLM_API_KEY="your-api-key" # Optional export LLM_API_BASE="your-api-base-url" # if using a local model, e.g. Ollama, LMStudio export PERPLEXITY_API_KEY="your-api-key" # for search capabilities ``` [πŸ“š View supported AI models](https://docs.litellm.ai/docs/providers) ## πŸ† Enterprise Platform Our managed platform provides: - **πŸ“ˆ Executive Dashboards** - **🧠 Custom Fine-Tuned Models** - **βš™οΈ CI/CD Integration** - **πŸ” Large-Scale Scanning** - **πŸ”Œ Third-Party Integrations** - **🎯 Enterprise Support** [**Get Enterprise Demo β†’**](https://form.typeform.com/to/ljtvl6X0) ## πŸ”’ Security Architecture - **Container Isolation** - All testing in sandboxed Docker environments - **Local Processing** - Testing runs locally, no data sent to external services > [!NOTE] > Strix is currently in Alpha. Expect rapid updates and improvements. > [!WARNING] > Only test systems you own or have permission to test. You are responsible for using Strix ethically and legally. ## 🌟 Support the Project **Love Strix?** Give us a ⭐ on GitHub! ## πŸ‘₯ Join Our Community Have questions? Found a bug? Want to contribute? **[Join our Discord!](https://discord.gg/yduEyduBsp)**