mirror of
https://github.com/usestrix/strix.git
synced 2026-08-21 02:45:31 +02:00
docs(skills): document --workspace-file for supporting files
This commit is contained in:
@@ -47,6 +47,7 @@ Out of scope: POST /billing/*, POST /notifications/broadcast."
|
||||
- **GraphQL:** point at the GraphQL endpoint and say whether introspection is enabled; call out that you want batching/aliasing abuse, depth/complexity limits, and per-field authorization tested.
|
||||
- **Internal/private APIs** unreachable from your machine: use the managed platform's network connector — see **managed-pentesting-with-strix**.
|
||||
- Use `--instruction-file` when the credential/context block gets long, and keep tokens out of shell history and out of committed files.
|
||||
- **Supporting files** the agents should read but not test, such as an endpoint wordlist or handwritten notes about the tenancy model: pass `--workspace-file ./notes.md`. The file lands read-only in `/workspace`. Add `:DEST` to choose the path, for example `--workspace-file ./wordlist.txt:lists/wordlist.txt`.
|
||||
|
||||
## 3. Verify findings
|
||||
|
||||
|
||||
@@ -75,6 +75,9 @@ strix -n -t ./openapi.yaml -t https://api.staging.example.com
|
||||
|
||||
# Many targets from a file, one per line
|
||||
strix -n --target-list ./targets.txt --max-budget 30
|
||||
|
||||
# Give the agents a file to work with (wordlist, spec, notes) without making it a target
|
||||
strix -n -t https://staging.example.com --workspace-file ./wordlist.txt --max-budget 20
|
||||
```
|
||||
|
||||
A local path passed with `-t` is mounted into the sandbox **writable** — the agents can read and modify it, so point at a clean checkout, not uncommitted work you care about.
|
||||
@@ -88,6 +91,7 @@ Key flags:
|
||||
| `-n, --non-interactive` | Headless, exits on completion. Required for agents. |
|
||||
| `-m, --scan-mode` | `quick` (minutes) / `standard` (~30 min) / `deep` (hours, default). |
|
||||
| `--instruction` / `--instruction-file` | Credentials, focus areas, scope rules. |
|
||||
| `--workspace-file PATH[:DEST]` | Place a file from this machine into `/workspace` read-only before the scan, for a wordlist, a spec, or notes. Repeatable. |
|
||||
| `--max-budget USD` | Hard LLM spend cap; scan wraps up cleanly at the limit. |
|
||||
| `--max-turns N` | Per-agent turn cap (default 500). |
|
||||
| `--resume RUN_NAME` | Resume a prior run from `strix_runs/`, with its agent history and targets. Cannot be combined with `-t`. |
|
||||
|
||||
Reference in New Issue
Block a user