Skip to main content

Open-source AI Hackers for your apps

Project description

Strix

Open-source AI hackers for your apps

Apache 2.0 Vercel AI Accelerator 2025 Status: Alpha Discord

⚡ Use it to hack your apps before the bad guys do ⚡

Strix Demo

🚨 The AI Security Crisis

Everyone's shipping code faster than ever. Cursor, Windsurf, and Claude made coding easy - but QA and security testing are now the real bottlenecks.

Number of security vulnerabilities doubled post-AI.

Traditional security tools weren't designed for this. SAST was a temporary fix when manual pentesting cost $10k+ and took weeks. Now, Strix delivers real security testing rapidly.

The solution: Enable developers to use AI coding at full speed, without compromising on security.

🦉 Strix Overview

Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual exploitation. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.

🚀 Quick Start

# Install
pipx install strix-agent

# Configure AI provider
export STRIX_LLM="anthropic/claude-sonnet-4-20250514"
export LLM_API_KEY="your-api-key"

# Run security assessment
strix --target ./app-directory

Why Use Strix

  • Full Hacker Arsenal - All the tools a professional hacker needs, built into the agents
  • Real Validation - Dynamic testing and actual exploitation, thus much fewer false positives
  • Developer-First - Seamlessly integrates into existing development workflows
  • Auto-Fix & Reporting - Automated patching with detailed remediation and security reports

✨ Features

🛠️ Agentic Security Tools

  • 🔌 Full HTTP Proxy - Full request/response manipulation and analysis
  • 🌐 Browser Automation - Multi-tab browser for testing of XSS, CSRF, auth flows
  • 💻 Terminal Environments - Interactive shells for command execution and testing
  • 🐍 Python Runtime - Custom exploit development and validation
  • 🔍 Reconnaissance - Automated OSINT and attack surface mapping
  • 📁 Code Analysis - Static and dynamic analysis capabilities
  • 📝 Knowledge Management - Structured findings and attack documentation

🎯 Comprehensive Vulnerability Detection

  • Access Control - IDOR, privilege escalation, auth bypass
  • Injection Attacks - SQL, NoSQL, command injection
  • Server-Side - SSRF, XXE, deserialization flaws
  • Client-Side - XSS, prototype pollution, DOM vulnerabilities
  • Business Logic - Race conditions, workflow manipulation
  • Authentication - JWT vulnerabilities, session management
  • Infrastructure - Misconfigurations, exposed services

🕸️ Graph of Agents

  • Distributed Workflows - Specialized agents for different attacks and assets
  • Scalable Testing - Parallel execution for fast comprehensive coverage
  • Dynamic Coordination - Agents collaborate and share discoveries

💻 Usage Examples

# Local codebase analysis
strix --target ./app-directory

# Repository security review
strix --target https://github.com/org/repo

# Web application assessment
strix --target https://your-app.com

# Focused testing
strix --target api.your-app.com --instruction "Prioritize authentication and authorization testing"

⚙️ Configuration

# Required
export STRIX_LLM="anthropic/claude-sonnet-4-20250514"
export LLM_API_KEY="your-api-key"

# Recommended
export PERPLEXITY_API_KEY="your-api-key"

📚 View supported AI models

🏆 Enterprise Platform

Our managed platform provides:

  • 📈 Executive Dashboards
  • 🧠 Custom Fine-Tuned Models
  • ⚙️ CI/CD Integration
  • 🔍 Large-Scale Scanning
  • 🔌 Third-Party Integrations
  • 🎯 Enterprise Support

Get Enterprise Demo →

🔒 Security Architecture

  • Container Isolation - All testing in sandboxed Docker environments
  • Local Processing - Testing runs locally, no data sent to external services

[!NOTE] Strix is currently in Alpha. Expect rapid updates and improvements.

[!WARNING] Only test systems you own or have permission to test. You are responsible for using Strix ethically and legally.

🌟 Support the Project

Love Strix? Give us a ⭐ on GitHub!

👥 Join Our Community

Have questions? Found a bug? Want to contribute? Join our Discord!


About • Links

OmniSecure Inc. • Applied AI Research Lab

Discord CommunityEnterprise SolutionsReport Issues

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

strix_agent-0.1.4.tar.gz (132.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

strix_agent-0.1.4-py3-none-any.whl (167.2 kB view details)

Uploaded Python 3

File details

Details for the file strix_agent-0.1.4.tar.gz.

File metadata

  • Download URL: strix_agent-0.1.4.tar.gz
  • Upload date:
  • Size: 132.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.0.0 CPython/3.12.8 Linux/6.13.8-arch1-1

File hashes

Hashes for strix_agent-0.1.4.tar.gz
Algorithm Hash digest
SHA256 3502be33627839e04d6d5aa7cc8cfb4c45393b1512dfba2a14352f4d49daa04c
MD5 03f8a7774a61f71e8f19abe41ec30126
BLAKE2b-256 348478a05b82d8ee966ca0d069d8d94a862c3095b22f08f36432cff3c98336b6

See more details on using hashes here.

File details

Details for the file strix_agent-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: strix_agent-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 167.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.0.0 CPython/3.12.8 Linux/6.13.8-arch1-1

File hashes

Hashes for strix_agent-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 634a82bc7b7af43ff5fe486c68e09633f7792b1b586a9a58441b43ff4a47eb86
MD5 ed8be189f02aabc971ac2fecfc557d27
BLAKE2b-256 db0b3bc630b94d9dd705a2c7c128194f0589aaaad8b985ca9ba2ddaafd7c2eaa

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page