usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

View on GitHub ↗Jump to charts ↓Open shareable report →

Data as of . Signed-in members get hourly updates — create a free account.

Summary Information

Updated 59 minutes ago
Added to GitGenius on November 8th, 2025
Created on August 5th, 2025
Open Issues & Pull Requests: 453 (+0)
GitHub issues: Enabled
Number of forks: 7,401
Total Stargazers: 67,362 (+20)
Total Subscribers: 294 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 24.6 hours
Mean response time: 13.1 days
90th percentile: 33.0 days
Tracked items: 294

How this project is maintained

Roughly one issue in four opened in the past year never receives a reply. 97% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. 34% of tracked open issues have had no activity in three months. Only 51% of issues opened in the past year have been closed. Three people close 83% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 185
New in 7 days: 6
Closed in 7 days: 7
Avg open age: 26 days
Stale 30+ days: 151
Stale 90+ days: 62

Recent activity

Opened in 7 days: 6
Closed in 7 days: 7
Comments in 7 days: 2
Events in 7 days: 6

Top labels

  • bug (132)
  • enhancement (88)
  • documentation (3)

Most active issues this week

Sign in to see which issues are moving.
Sign in

Detailed Description

Strix is an open-source AI penetration testing tool that autonomously finds and fixes application vulnerabilities.

The tool addresses the gap between manual penetration testing and static analysis by deploying autonomous AI agents that behave like real hackers. Rather than relying on pattern matching or signature detection, Strix runs code dynamically, identifies vulnerabilities, and validates them through actual proofs-of-concept. This approach eliminates false positives common in legacy vulnerability scanners while reducing the cost and time overhead of hiring human penetration testers. The system uses multi-agent orchestration, allowing teams of AI pentesters to collaborate and scale across testing tasks.

Strix suits development teams and security organizations that need fast, accurate security testing integrated into their workflow. It provides a developer-first CLI with actionable findings and remediation guidance, and integrates with GitHub Actions and CI/CD pipelines to scan for vulnerabilities on every pull request. The tool generates working exploits as proof-of-concept rather than theoretical findings, and can auto-generate patches alongside compliance-ready pentest reports. This makes it particularly valuable for teams seeking to shift security testing left without the friction of manual processes.

The project maintains a substantial base of adopters who report real-world issues, with almost all open issues raised by outside users rather than the core team. Maintainers typically respond to new issues and pull requests within a few days. Work in the issue tracker is dominated by bug fixes, enhancements, and documentation improvements.