11st of 1 in Security
Strix
Autonomous AI pentesting agents that validate findings with working exploits
Documentation ↗
(opens in a new tab)Website ↗
(opens in a new tab)Repository on GitHub ↗
(opens in a new tab)
- Stars
- 67.7k
- License
- Apache-2.0
- Last commit
- Oct 2026
- Last release
- Oct 2026
- Language
- Python
Overview
CLI that runs a team of LLM agents (recon, exploitation, post-exploitation) against a local codebase, GitHub repo, live URL or OpenAPI/Postman spec. Agents work in a Docker sandbox with a Caido HTTP proxy, a Playwright browser, a shell and a Python exploit runtime, and each finding needs a working proof-of-concept. Installed by a curl script (PyPI package strix-agent); STRIX_LLM takes LiteLLM-style model strings, so OpenAI, Anthropic, Google, Bedrock, Azure, OpenRouter or a local Ollama/LM Studio endpoint all work.
Who it is for: Developers and security teams automating app pentests locally or in CI
Strengths
- Each finding is validated with a working proof-of-concept exploit, not just a pattern match
- Targets code, GitHub repos, live URLs, OpenAPI/Swagger and Postman specs, or a target list
- Headless mode exits non-zero on findings; GitHub Actions runs scope to changed files
- Local web viewer (strix view) reads run results from disk, bound to 127.0.0.1
Weaknesses
- Needs Docker running; the first run pulls the sandbox image
- Requires an LLM API key; local models only via LLM_API_BASE (Ollama, LM Studio)
- Autofix PRs, continuous scanning and Jira/Slack hooks are Cloud; SSO and compliance reports are Enterprise
- README documents install only as curl | bash, though a PyPI package (strix-agent) exists
What it needs
- no GPU
- Docker
- Needs docker, LLM API key
- Models: OpenAI, Anthropic, Google / Vertex AI, OpenRouter, DeepSeek