Skip to content
repository radar
Security

🦉strix

ACTIVE BREAKOUT

usestrix/strix · homepage ↗

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

⭐ Hugely popular: 53k stars, gaining about 3k a week

View on GitHub ↗

repo profile

vintage 2025 1 year old
delivery product
language Python
license Apache-2.0

momentum

total stars 53k
stars added last week +3k
HN peak 102 pts 0y 12mo ago
binary downloads 6k total · GitHub releases
commits / week 34 accelerating · +63% vs prior mo
issues closed 72% ~8d to close, median
contributors 67 (+2 in 15d)
release cadence weekly
last activity yesterday

durability

backing VC-backed Strix ($117M raised)
openness permissive
bus factor 1 solo
top-author share 57% 6 mo

bus factor = how many people it takes to cover more than half the commits (6 months). 1 is a solo project; higher means the work is spread across a team. top-author share is the single busiest author's slice of those commits.

since we covered it

monthly average + 5k/mo (+49%/mo) · + 43k total since PR#21

why it's a big deal

  • It is the same generalist agent pointed at a different trade: give it a security toolkit and it becomes a penetration tester that validates findings, not a scanner that guesses.
  • Real proof-of-concepts are the whole point - it reproduces a vulnerability before reporting it, which is the difference between a fixable ticket and static-analysis noise.
  • A “graph of agents” turns one tester into a team - specialized agents split across attack surfaces and run in parallel, the way a real red team would.

under the hood

  • A full toolkit out of the box: an HTTP proxy, multi-tab browser automation for XSS and auth flows, interactive shells, a Python runtime for custom exploits, recon and OSINT, and static plus dynamic code analysis.
  • Multi-agent orchestration that distributes specialized agents across assets and shares discoveries between them as they go.
  • CLI-first with a headless mode and GitHub Actions integration, so a pull request can be pentested and auto-fix PRs proposed; built on LiteLLM, Caido, Nuclei, Playwright, and Textual.

our take from PR#37, 2026-07-01

star history

PR#21 · 10k PR#37 · 28k53k now Aug 2025Aug 2026
  1. PR#21 10k 2025-11-12
  2. PR#37 28k 2026-07-01
  3. now 53k + 43k since first covered

curve is sampled from GitHub's star history, plus our own daily readings since we covered it; the dashed stretch is before we first covered it, the solid line since. figures at coverage are the numbers we printed then (approx.), current count is live.

understory

Output and attention are roughly in balance.

-10 understory score output 73 · clout 83
Aug 2025 Jul 2026
  • output, commits & releases
  • clout, star velocity

output = commits & releases; clout = star velocity, both 0 to 100 monthly indices; the gap where output runs above clout is the understory. The understory →

covered in

  • PR#37 2026-07-01 on the radar

    A coding agent handed a hacker’s toolkit

  • PR#21 2025-11-12 below the radar

    Agent-powered pentesting in minutes

similar projects

compare these →
  • 🕷️ PentAGI

    Go · leaner, 22k stars

    Fully autonomous AI Agents system capable of performing complex penetration testing tasks

    22k ACTIVE
  • 🔒 nono

    Rust · leaner, 4k stars

    Sandbox any AI agent in seconds - zero setup, zero latency.

    4k ACTIVE
  • 🧠 Flowise

    TypeScript

    Build AI Agents, Visually

    55k OFF THE RADAR

comments

Sign in with GitHub to add your blip on strix.

loading comments…