🦉strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
⭐ Hugely popular: 53k stars, gaining about 3k a week
View on GitHub ↗repo profile
momentum
durability
bus factor = how many people it takes to cover more than half the commits (6 months). 1 is a solo project; higher means the work is spread across a team. top-author share is the single busiest author's slice of those commits.
since we covered it
why it's a big deal
- It is the same generalist agent pointed at a different trade: give it a security toolkit and it becomes a penetration tester that validates findings, not a scanner that guesses.
- Real proof-of-concepts are the whole point - it reproduces a vulnerability before reporting it, which is the difference between a fixable ticket and static-analysis noise.
- A “graph of agents” turns one tester into a team - specialized agents split across attack surfaces and run in parallel, the way a real red team would.
under the hood
- A full toolkit out of the box: an HTTP proxy, multi-tab browser automation for XSS and auth flows, interactive shells, a Python runtime for custom exploits, recon and OSINT, and static plus dynamic code analysis.
- Multi-agent orchestration that distributes specialized agents across assets and shares discoveries between them as they go.
- CLI-first with a headless mode and GitHub Actions integration, so a pull request can be pentested and auto-fix PRs proposed; built on LiteLLM, Caido, Nuclei, Playwright, and Textual.
our take from PR#37, 2026-07-01
star history
curve is sampled from GitHub's star history, plus our own daily readings since we covered it; the dashed stretch is before we first covered it, the solid line since. figures at coverage are the numbers we printed then (approx.), current count is live.
understory
Output and attention are roughly in balance.
- output, commits & releases
- clout, star velocity
output = commits & releases; clout = star velocity, both 0 to 100 monthly indices; the gap where output runs above clout is the understory. The understory →
covered in
-
A coding agent handed a hacker’s toolkit
-
Agent-powered pentesting in minutes
similar projects
compare these →- 🕷️ PentAGI
Go · leaner, 22k stars
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
22k ACTIVE - 🔒 nono
Rust · leaner, 4k stars
Sandbox any AI agent in seconds - zero setup, zero latency.
4k ACTIVE - 🧠 Flowise
TypeScript
Build AI Agents, Visually
55k OFF THE RADAR
comments
Sign in with GitHub to add your blip on strix.