usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 21 minutes ago
Added to GitGenius on November 8th, 2025
Created on August 5th, 2025
Open Issues & Pull Requests: 319 (+0)
Number of forks: 6,243
Total Stargazers: 57,544 (+2)
Total Subscribers: 262 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 22.0 hours
Mean response time: 13.4 days
90th percentile: 33.0 days
Tracked items: 261

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 96% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. 22% of tracked open issues have had no activity in three months. Only 11% of issues opened in the past year have been closed. Three people close 84% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 138
New in 7 days: 20
Closed in 7 days: 5
Avg open age: 30 days
Stale 30+ days: 81
Stale 90+ days: 31

Recent activity

Opened in 7 days: 18
Closed in 7 days: 5
Comments in 7 days: 36
Events in 7 days: 66

Top labels

  • bug (106)
  • enhancement (71)
  • documentation (3)

Detailed Description

Strix is an open-source AI penetration testing tool that autonomously finds and fixes application vulnerabilities.

The tool addresses the gap between manual penetration testing and static analysis by deploying autonomous AI agents that behave like real hackers. Rather than relying on pattern matching or signature detection, Strix runs code dynamically, identifies vulnerabilities, and validates them through actual proofs-of-concept. This approach eliminates false positives common in legacy vulnerability scanners while reducing the cost and time overhead of hiring human penetration testers. The system uses multi-agent orchestration, allowing teams of AI pentesters to collaborate and scale across testing tasks.

Strix suits development teams and security organizations that need fast, accurate security testing integrated into their workflow. It provides a developer-first CLI with actionable findings and remediation guidance, and integrates with GitHub Actions and CI/CD pipelines to scan for vulnerabilities on every pull request. The tool generates working exploits as proof-of-concept rather than theoretical findings, and can auto-generate patches alongside compliance-ready pentest reports. This makes it particularly valuable for teams seeking to shift security testing left without the friction of manual processes.

The project maintains a substantial base of adopters who report real-world issues, with almost all open issues raised by outside users rather than the core team. Maintainers typically respond to new issues and pull requests within a few days. Work in the issue tracker is dominated by bug fixes, enhancements, and documentation improvements.