Strix
Open-source AI pentesting agents that test applications, validate vulnerabilities with proofs of concept, and produce actionable reports.
Quick verdict: Strix is an open-source AI pentesting tool for developers and security teams who want an agent to probe an application, confirm exploitable weaknesses, and turn the evidence into an actionable report. Its strongest idea is validation: the system is designed to test a suspected issue and produce a proof of concept instead of returning a long list of unverified scanner alerts. The important catch is that this is offensive security software, not a casual code-quality checker. It needs Docker, a capable language model, a clearly authorized target, and someone who understands how to review potentially dangerous results.
Overview
Strix runs autonomous AI agents equipped with a browser, an HTTP interception proxy, a terminal, a Python runtime, reconnaissance utilities, and code-analysis tools. You can point it at a local repository, a GitHub repository, a live web application, an API description, or multiple related targets. The agents explore the attack surface, coordinate their work, attempt to reproduce vulnerabilities, and save the run locally.
The project offers two paths. The Apache-2.0 command-line edition runs on your own machine or infrastructure with your chosen model provider. A managed Strix platform removes the local Docker and model-key setup while adding hosted dashboards, repository integrations, scheduled testing, and team workflows. That split makes the open-source core useful for experimentation and controlled internal work, while teams that want less operational overhead can evaluate the hosted service separately.
Main Features
- Agentic penetration testing: specialized agents perform reconnaissance, code analysis, browser interaction, request manipulation, exploitation, and validation.
- Proof-oriented findings: reports can include a working proof of concept, reproduction steps, severity information, affected endpoints, and remediation guidance.
- White-box and black-box targets: scan source code, a remote repository, a running application, an API contract, or a combination of code and deployed service.
- Interactive and headless modes: use the terminal interface for guided work or run non-interactively in automation and CI/CD.
- Local run viewer: open a token-protected browser dashboard for run status, vulnerabilities, agent activity, history, steering, and reports.
- Model-provider choice: configure OpenAI, Anthropic, Google, OpenRouter, Azure, Bedrock, and documented local-model routes.
- Developer workflow support: the project documents GitHub Actions, pull-request scanning, SARIF-style workflows, coding-agent skills, and MCP server access.
The official demo below shows what “validated” means in practice. Strix has confirmed a business-logic flaw that accepts a negative quantity, records the exploit outcome, assigns a severity and CVSS score, and identifies the relevant endpoints. This is much more useful than a generic warning, although a human still needs to verify the scope, business impact, and proposed fix.

Product Highlights
Strix is particularly interesting when static analysis is not enough. Its agents can combine source context with a running target, manipulate requests, exercise browser flows, and chain discoveries across agents. The documented coverage includes access-control failures, SQL and command injection, SSRF, XXE, unsafe deserialization, XSS, authentication weaknesses, API problems, infrastructure mistakes, and business-logic flaws. No automated tool can guarantee complete coverage, but the ability to test behavior dynamically gives Strix a useful role alongside linters, dependency scanners, and human review.
The local viewer is another practical detail. A scan writes artifacts under strix_runs, and strix view serves those files through a lightweight dashboard bound to localhost by default. The viewer includes an overview, validated findings, an agent graph, steering controls, run history, and report generation. If you expose it on another interface, treat the tokenized URL as a credential and protect the port; scan evidence may contain source details, endpoints, payloads, or secrets.
How to Use Strix
The official Quick Start keeps the first run short, but the prerequisites matter. Docker must be running, and the local edition needs an API key for a supported LLM provider. The package metadata currently requires Python 3.12 or newer when installing through Python tooling. The project also provides a shell installer for supported macOS and Linux setups.

- Choose a system you own or have explicit written permission to test, and define the allowed hosts, accounts, time window, techniques, and data-handling rules.
- Start Docker, install Strix with the official installer, and review the installer before executing it in a sensitive environment.
- Set
STRIX_LLMto a supported model route and provide the corresponding API key through the documented environment variable. - Begin with a disposable lab or a small local application: run
strix --target ./your-app. - Watch the interactive session, or use
-nfor a headless run in automation. Narrow instructions are safer than an open-ended assessment. - Open the saved result with
strix view, inspect every proof of concept, and reproduce important findings manually before changing production code. - Fix confirmed issues, run focused regression tests, and re-scan the authorized target to verify that the exploit no longer works.
For APIs, Strix can accept OpenAPI, Swagger, or Postman material alongside the live base URL. For CI, use headless mode and pin a tested release instead of piping the newest installer into every production job. Keep model keys and target credentials in a secret manager, limit network access from the sandbox, and store reports as sensitive security data.
Use Cases
Good fits include pre-release testing of a web application, source-assisted API review, validation of a suspicious business-logic path, security checks on pull requests, repeatable testing in a private lab, and an initial pass before a human pentest. Bug-bounty researchers may also appreciate the proof-oriented workflow, provided every action stays inside the program’s published scope and rules.
It is a poor fit for scanning arbitrary internet targets, replacing an independent compliance assessment, or giving an unattended agent broad access to a production network. Model behavior is probabilistic, exploit attempts can change data or trigger defenses, and a missed vulnerability is not evidence that an application is secure. Use Strix as one layer in a broader program that includes threat modeling, secure development, dependency management, conventional scanners, manual review, logging, backups, and incident response.
Pricing and License
The open-source repository is licensed under Apache-2.0, so there is no Strix license fee for running the core software under that license’s terms. Version 1.5.3 is declared in the current package metadata, and the repository received a viewer security fix on September 1, 2026 Beijing time, indicating active maintenance at the time of this review. Local use can still cost money: model API calls, compute, Docker storage, engineering time, and security review all have real costs.
The hosted platform has separate commercial pricing. The official pricing page currently lists a Pro plan from $29 per seat per month with pentests billed separately, a seven-day trial, custom Enterprise pricing, and one-time pentests from $1,000. Prices and inclusions can change, so confirm them on the official page before budgeting. Organizations handling confidential repositories should also review the hosted service’s current terms, data provisions, deployment options, and model configuration before connecting production assets.
Practical Limitations and Safety
The biggest limitation is operational risk. Strix is intended to behave like an attacker and may send exploit payloads, create test records, exercise authentication, or consume significant model and compute resources. Run it against an isolated copy first, use least-privilege credentials, exclude destructive paths, keep backups, and make sure monitoring teams know the test is scheduled. The repository explicitly warns users to test only systems they own or are authorized in writing to assess.
Quality varies with the target, instructions, model, available context, and defensive controls. Proofs of concept reduce false-positive noise, but they do not remove the need for judgment. Auto-generated patches can introduce regressions, cloud scans involve a different data path from local scans, and local operation may still send prompts and code context to a remote model provider. Review the complete route for source, credentials, traffic captures, and reports before using confidential data.
Final Verdict
Strix is worth evaluating if your team wants an inspectable AI security agent that goes beyond pattern matching and tries to prove what is exploitable. Its multi-agent workflow, dynamic tools, local viewer, CI options, provider choice, and Apache-2.0 core make it unusually accessible for an advanced pentesting project. Start in a lab, define scope tightly, keep a human in control, and judge it by the quality and reproducibility of confirmed findings rather than by the number of alerts it produces.
