11st of 1 in Security

Strix

Autonomous AI pentesting agents that validate findings with working exploits

Stars
67.7k
License
Apache-2.0
Last commit
Oct 2026
Last release
Oct 2026
Language
Python

Overview

CLI that runs a team of LLM agents (recon, exploitation, post-exploitation) against a local codebase, GitHub repo, live URL or OpenAPI/Postman spec. Agents work in a Docker sandbox with a Caido HTTP proxy, a Playwright browser, a shell and a Python exploit runtime, and each finding needs a working proof-of-concept. Installed by a curl script (PyPI package strix-agent); STRIX_LLM takes LiteLLM-style model strings, so OpenAI, Anthropic, Google, Bedrock, Azure, OpenRouter or a local Ollama/LM Studio endpoint all work.

Who it is for: Developers and security teams automating app pentests locally or in CI

Strengths

  • Each finding is validated with a working proof-of-concept exploit, not just a pattern match
  • Targets code, GitHub repos, live URLs, OpenAPI/Swagger and Postman specs, or a target list
  • Headless mode exits non-zero on findings; GitHub Actions runs scope to changed files
  • Local web viewer (strix view) reads run results from disk, bound to 127.0.0.1

Weaknesses

  • Needs Docker running; the first run pulls the sandbox image
  • Requires an LLM API key; local models only via LLM_API_BASE (Ollama, LM Studio)
  • Autofix PRs, continuous scanning and Jira/Slack hooks are Cloud; SSO and compliance reports are Enterprise
  • README documents install only as curl | bash, though a PyPI package (strix-agent) exists

What it needs

  • no GPU
  • Docker
  • Needs docker, LLM API key
  • Models: OpenAI, Anthropic, Google / Vertex AI, OpenRouter, DeepSeek