Security

AI agents and tools for penetration testing, red-teaming and finding vulnerabilities in your own apps and models.

Strix leads with 69. 1 projects ranked by score.

The ranking

Security: full ranking
RankProjectAdoptionFreshnessMaintenanceEasy to runAgent-readyScore
1StrixAutonomous AI pentesting agents that validate findings with working exploits67.7k stars, Apache-2.0, last commit Oct 20269410078333069 out of 100

Momentum, Verified build, Docs and Privacy are not measured yet; their weight goes to the signals shown. A dash means the signal is not scored for that kind of project. Hover a number for its rating in words.

Reviews

169 out of 100

Strix

Autonomous AI pentesting agents that validate findings with working exploits

67.7k stars, Apache-2.0, last commit Oct 2026

CLI that runs a team of LLM agents (recon, exploitation, post-exploitation) against a local codebase, GitHub repo, live URL or OpenAPI/Postman spec. Agents work in a Docker sandbox with a Caido HTTP proxy, a Playwright browser, a shell and a Python exploit runtime, and each finding needs a working proof-of-concept. Installed by a curl script (PyPI package strix-agent); STRIX_LLM takes LiteLLM-style model strings, so OpenAI, Anthropic, Google, Bedrock, Azure, OpenRouter or a local Ollama/LM Studio endpoint all work.

Strengths

  • Each finding is validated with a working proof-of-concept exploit, not just a pattern match
  • Targets code, GitHub repos, live URLs, OpenAPI/Swagger and Postman specs, or a target list
  • Headless mode exits non-zero on findings; GitHub Actions runs scope to changed files
  • Local web viewer (strix view) reads run results from disk, bound to 127.0.0.1

Weaknesses

  • Needs Docker running; the first run pulls the sandbox image
  • Requires an LLM API key; local models only via LLM_API_BASE (Ollama, LM Studio)
  • Autofix PRs, continuous scanning and Jira/Slack hooks are Cloud; SSO and compliance reports are Enterprise
  • README documents install only as curl | bash, though a PyPI package (strix-agent) exists
  • no GPU
  • Docker
  • Needs docker, LLM API key
  • Models: OpenAI, Anthropic, Google / Vertex AI, OpenRouter, DeepSeek

Written from each project's README and checked facts. Spot something wrong? Report it on GitHub (opens in a new tab).