mirror of
https://github.com/usestrix/strix.git
synced 2026-08-21 18:52:47 +02:00
docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill
- Remove --mount from two skills: the flag does not exist in the CLI. Local paths are mounted writable when passed with -t. - Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman targets, so agents stop putting spec URLs in --instruction prose. - Add the application-security-testing skill as the entry point for whole-product AppSec requests, routing each asset to the right workflow. - Drop contractions and Latin abbreviations across the skill prose.
This commit is contained in:
@@ -19,6 +19,7 @@ npx skills add usestrix/strix
|
||||
| `managed-pentesting-with-strix` | Drive the managed [app.strix.ai](https://app.strix.ai) platform over REST — no local Docker or LLM key needed |
|
||||
| `fix-security-vulnerabilities-with-strix` | Triage findings, fix root causes, and re-run Strix to verify each fix |
|
||||
| `ci-security-scanning-with-strix` | Add PR security scanning to GitHub Actions or any CI (self-hosted CLI or managed app) |
|
||||
| `application-security-testing` | Assess a whole product: choose the right test for each asset, then rank the findings into one remediation plan |
|
||||
| `web-app-penetration-testing` | Black-box pentest of a live web app or staging site — scope, credentials, and multi-account access-control testing |
|
||||
| `api-security-testing` | Test a REST/GraphQL API against the OWASP API Security Top 10 — schema-driven enumeration, BOLA/IDOR, authz |
|
||||
| `owasp-top-10-testing` | Systematic OWASP Top 10 assessment with honest per-category coverage |
|
||||
|
||||
Reference in New Issue
Block a user