Strix: an open source AI penetration testing tool that allows AI to run applications like a real hacker, find vulnerabilities and provide repair patchesStrix:开源 AI 渗透测试工具,让 AI 像真黑客一样把应用跑起来、找出漏洞并给出修复补丁
An autonomous penetration testing agent with 66,000 stars. The biggest difference between it and traditional scanners is "verification": AI does not just report a suspicious point, but actually runs the application, constructs a reproducible PoC to prove the existence of the vulnerability, and then provides patches and compliance-level reports. The entire attack toolchain—HTTP interception proxy, browser exploits, shell, Python vulnerability runtime, reconnaissance and OSINT, SAST+DAST—is available out of the box.
6.6 万 Star 的自主渗透测试智能体。它和传统扫描器最大的区别是「验证」:AI 不是只报一个可疑点,而是真的把应用跑起来、构造可复现的 PoC 证明漏洞存在,再给出补丁与合规级报告。整套攻击工具链——HTTP 拦截代理、浏览器利用、Shell、Python 漏洞运行时、侦察与 OSINT、SAST+DAST——都是开箱即用。

Why it's worth trying为什么值得试
Real vulnerabilities, no false positives: Each conclusion is accompanied by a working PoC and reproduction steps, which not only saves the cycle cost of manual penetration, but also avoids the problem of false positives caused by static analysis tools.
Multi-agent collaboration: Multiple AI penetration testers work together and deploy in parallel, covering the entire process of reconnaissance, utilization, and verification, and automatically generate repair patches and compliance reports.
真漏洞、非误报:每个结论都附一份能跑通的利用 PoC 与复现步骤,既省掉人工渗透的周期成本,也避开静态分析工具漫天误报的毛病。
多智能体协作:多个 AI 渗透测试员分工协作、并行铺开,覆盖侦察、利用、验证全流程,并自动生成修复补丁与合规报告。

What capabilities does it come with?它自带哪些能力
Attack tool chain: Caido HTTP interception proxy, automatic browser testing for XSS/CSRF/clickjacking/authentication bypass, interactive terminal, Python vulnerability sandbox.
Covers the OWASP Top 10: common high-risk aspects such as unauthorized access (IDOR, privilege escalation, authentication bypass), injection classes (SQL / NoSQL / command injection / SSTI), and provides CVSS scores and OWASP classifications.
攻击工具链:Caido HTTP 拦截代理、可自动操作浏览器测 XSS / CSRF / 点击劫持 / 鉴权绕过、交互式终端、Python 漏洞沙箱。
覆盖 OWASP Top 10:越权访问(IDOR、提权、鉴权绕过)、注入类(SQL / NoSQL / 命令注入 / SSTI)等常见高危面,并给出 CVSS 评分与 OWASP 分类。

How to run怎么跑起来
Prerequisites: Install and start Docker on this machine, and then prepare a large model API Key from any supported manufacturer (OpenAI, Anthropic, Google, etc.).
Three steps to start: curl -sSL https://strix.ai/install | bash installation; set the two environment variables STRIX_LLM and LLM_API_KEY; then strix --target ./your project directory to start the first security assessment. The first run will automatically pull the sandbox image, and the result will be saved in strix_runs/<run-name>.
It can also be installed into programming agents: npx skills add usestrix/strix will install 9 skills, allowing Claude Code, Cursor, and Codex to directly have the ability to run penetrations, fix vulnerabilities, and connect to CI.
前置条件:本机装好并启动 Docker,再准备任意一家受支持厂商的大模型 API Key(OpenAI、Anthropic、Google 等)。
三步起步:curl -sSL https://strix.ai/install | bash 安装;设置 STRIX_LLM 与 LLM_API_KEY 两个环境变量;然后 strix --target ./你的项目目录 开始第一次安全评估。首次运行会自动拉取沙箱镜像,结果保存在 strix_runs/<run-name>。
它也能装进编程智能体:npx skills add usestrix/strix 会装好 9 个技能,让 Claude Code、Cursor、Codex 直接具备跑渗透、修漏洞、接 CI 的能力。
Download instructions下载说明
The download button provides the complete source code package of the project's main branch (about 5.2 MB), including CLI, multi-agent orchestration, vulnerability knowledge base and documentation, and is licensed under Apache-2.0. Python users can also install directly via pip install strix-agent.
下载按钮提供项目 main 分支完整源码包(约 5.2 MB),含 CLI、多智能体编排、漏洞知识库与文档,Apache-2.0 许可。Python 用户也可以直接 pip install strix-agent 安装。
Use reminder使用提醒
Penetration testing tools can only be used on targets that you own or have written authorization for; it may be illegal to initiate tests on other people's systems without authorization. Calling third-party large model APIs will incur fees, please evaluate them yourself. This article is compiled from public information, and the resources are only for learning and exchange.
渗透测试工具只能用于你拥有或已获得书面授权的目标;未经授权对他人系统发起测试可能违法。调用第三方大模型 API 会产生费用,请自行评估。本文整理自公开资料,资源仅供学习交流。
⬇ Download · 点击下载:Strix main 分支源码包(约 5.2 MB)
来自 GitHub 开源仓库 usestrix/strix(Apache-2.0 许可),含 CLI、多智能体编排与漏洞知识库
阅读与点赞数据保存在你的浏览器本地,欢迎留下你的想法。
今日正能量学一点,用一点;今天种下的种子,会长成明天的能力。去免费下载专区 →广告
评论 文明发言,让讨论更有价值