7acd2be925
feat: Add NoSQL injection vulnerability guide ( #168 )
...
* feat: Add NoSQL injection vulnerability guide
This file provides a comprehensive guide on NoSQL injection vulnerabilities, detailing methodologies, injection surfaces, detection channels, and prevention strategies across various NoSQL databases.
* Address NoSQL injection review feedback
---------
Co-authored-by: bearsyankees <bearsyankees@gmail.com >
2026-04-22 13:23:14 -04:00
alex s and GitHub
1f908a0328
fix: ensure LLM stats tracking is accurate by including completed subagents ( #441 )
2026-04-13 00:09:13 -04:00
Ahmed Allam and GitHub
737c9d97ac
Add Strix GitHub Actions integration tip
2026-04-12 12:43:41 -07:00
STJ and GitHub
b5d1d8c833
feat: Migrate from Poetry to uv ( #379 )
2026-03-31 17:20:41 -07:00
alex s and GitHub
51834e6649
feat: Better source-aware testing ( #391 )
2026-03-31 11:53:49 -07:00
0xallam and Ahmed Allam
0bd52c14d7
chore: bump version to 0.8.3
2026-03-22 22:10:17 -07:00
0xallam and Ahmed Allam
2947420801
fix: use anthropic model in anthropic provider docs example
2026-03-22 22:08:20 -07:00
0xallam and Ahmed Allam
a95f6aaa6e
fix: strengthen tool-call requirement in interactive and autonomous modes
...
Models occasionally output text-only narration ("Planning the
assessment...") without a tool call, which halts the interactive agent
loop since the system interprets no-tool-call as "waiting for user
input." Rewrite both interactive and autonomous prompt sections to make
the tool-call requirement absolute with explicit warnings about the
system halt consequence.
2026-03-22 22:08:20 -07:00
0xallam and Ahmed Allam
ef05934b94
chore: bump sandbox image to 0.1.13
2026-03-22 22:08:20 -07:00
0xallam and Ahmed Allam
412b2ace24
refine system prompt, add scope verification, and improve tool guidance
...
- Rewrite system prompt: refusal avoidance, system-verified scope, thorough
validation mandate, root agent orchestration role, recon-first guidance
- Add authorized targets injection via system_prompt_context in strix_agent
- Add set_system_prompt_context to LLM for dynamic prompt updates
- Prefer python tool over terminal for Python code in tool schemas
- Increase LLM retry backoff cap to 90s
- Replace models.strix.ai footer with strix.ai
2026-03-22 22:08:20 -07:00
0xallam and Ahmed Allam
55b175498a
chore: update default model to gpt-5.4 and remove Strix Router from docs
...
- Change default model from gpt-5 to gpt-5.4 across docs, tests, and examples
- Remove Strix Router references from docs, quickstart, overview, and README
- Delete models.mdx (Strix Router page) and its nav entry
- Simplify install script to suggest openai/ prefix directly
- Keep strix/ model routing support intact in code
2026-03-22 22:08:20 -07:00
Ahmed Allam
71e79a2f2c
Simplify tool file copying in Dockerfile
...
Removed specific tool files from Dockerfile and added a directory copy instead.
2026-03-22 16:01:39 -07:00
0xallam and Ahmed Allam
060adbd2cd
fix: address review feedback on tool registration gating
2026-03-19 23:50:57 -07:00
0xallam and Ahmed Allam
f964d76855
refactor: move tool availability checks into registration
2026-03-19 23:50:57 -07:00
Ahmed Allam and GitHub
e74a766284
Guard TUI chat rendering against invalid Rich spans ( #375 )
2026-03-19 22:28:42 -07:00
Ahmed Allam and GitHub
e86fc1d225
fix: prevent ScreenStackError when stopping agent from modal ( #374 )
2026-03-19 20:39:05 -07:00
fa2db928d0
feat: add skills for specific tools ( #366 )
...
Co-authored-by: 0xallam <ahmed39652003@gmail.com >
2026-03-19 16:47:29 -07:00
Ahmed Allam
04878d49c7
Add tip about Strix integration with GitHub Actions
2026-03-17 22:14:11 -07:00
0xallam and Ahmed Allam
03e1b9396a
feat: add interactive mode for agent loop
...
Re-architects the agent loop to support interactive (chat-like) mode
where text-only responses pause execution and wait for user input,
while tool-call responses continue looping autonomously.
- Add `interactive` flag to LLMConfig (default False, no regression)
- Add configurable `waiting_timeout` to AgentState (0 = disabled)
- _process_iteration returns None for text-only → agent_loop pauses
- Conditional system prompt: interactive allows natural text responses
- Skip <meta>Continue the task.</meta> injection in interactive mode
- Sub-agents inherit interactive from parent (300s auto-resume timeout)
- Root interactive agents wait indefinitely for user input (timeout=0)
- TUI sets interactive=True; CLI unchanged (non_interactive=True)
2026-03-14 11:57:58 -07:00
0xallam and Ahmed Allam
1937688b07
fix: web_search tool not loading when API key is in config file
...
The perplexity API key check in strix/tools/__init__.py used
Config.get() which only checks os.environ. At import time, the
config file (~/.strix/cli-config.json) hasn't been applied to
env vars yet, so the check always returned False.
Replace with _has_perplexity_api() that checks os.environ first
(fast path for SaaS/env var), then falls back to Config.load()
which reads the config file directly.
2026-03-14 11:48:45 -07:00
Ahmed Allam
ed89e3c4d1
Update web search model name to 'sonar-reasoning-pro'
2026-03-11 14:20:04 -07:00
Alex and Ahmed Allam
bc2ae4ea94
Change VERTEXAI_LOCATION from 'us-central1' to 'global'
...
us-central1 doesn't have access to the latest gemini models like gemini-3-flash-preview
2026-03-11 08:08:18 -07:00
e4284097f5
Add OpenTelemetry observability with local JSONL traces ( #347 )
...
Co-authored-by: 0xallam <ahmed39652003@gmail.com >
2026-03-09 01:11:24 -07:00
0xallam and GitHub
de7768bd8a
chore(deps): bump pypdf from 6.7.4 to 6.7.5 ( #343 )
2026-03-08 09:46:32 -07:00
Ms6RB and GitHub
e13a74a7b6
feat(skills): add NestJS security testing module ( #348 )
2026-03-08 09:45:08 -07:00
0xallam and Ahmed Allam
5f38cc0f1c
chore(deps): bump pypdf from 6.7.2 to 6.7.4
...
Bumps [pypdf](https://github.com/py-pdf/pypdf ) from 6.7.2 to 6.7.4.
- [Release notes](https://github.com/py-pdf/pypdf/releases )
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md )
- [Commits](https://github.com/py-pdf/pypdf/compare/6.7.2...6.7.4 )
---
updated-dependencies:
- dependency-name: pypdf
dependency-version: 6.7.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-02 15:34:01 -08:00
Ahmed Allam and GitHub
a4bf8cc8e2
Update README
2026-03-03 03:33:46 +04:00
Ahmed Allam and GitHub
a6dbeaa724
Update models.mdx
2026-03-03 03:33:14 +04:00
octovimmer and Ahmed Allam
f6120b0a41
chore: remove references of codex models
2026-03-02 15:29:29 -08:00
octovimmer and Ahmed Allam
30eec7fc98
chore: remove codex models from supported models
2026-03-02 15:29:29 -08:00
0xallam and Ahmed Allam
a1d5be1050
chore(deps): bump pypdf from 6.7.1 to 6.7.2
...
Bumps [pypdf](https://github.com/py-pdf/pypdf ) from 6.7.1 to 6.7.2.
- [Release notes](https://github.com/py-pdf/pypdf/releases )
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md )
- [Commits](https://github.com/py-pdf/pypdf/compare/6.7.1...6.7.2 )
---
updated-dependencies:
- dependency-name: pypdf
dependency-version: 6.7.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-26 14:58:52 -08:00
0xallam
91724b1a24
docs: Add Strix Platform and Enterprise sections to README
2026-02-26 14:58:28 -08:00
0xallam
f22b058cff
docs: Add human-in-the-loop section to proxy documentation
2026-02-23 19:54:54 -08:00
0xallam
f5e3ceed7f
chore: Bump version to 0.8.2
2026-02-23 18:41:06 -08:00
0xallam and Ahmed Allam
35174dced2
feat: Expose Caido proxy port to host for human-in-the-loop interaction
...
Users can now access the Caido web UI from their browser to inspect traffic,
replay requests, and perform manual testing alongside the automated scan.
- Map Caido port (48080) to a random host port in DockerRuntime
- Add caido_port to SandboxInfo and track across container lifecycle
- Display Caido URL in TUI sidebar stats panel with selectable text
- Bind Caido to 0.0.0.0 in entrypoint (requires image rebuild)
- Bump sandbox image to 0.1.12
- Restore discord link in exit screen
2026-02-23 18:37:25 -08:00
mason5052 and Ahmed Allam
8c7a3102f9
docs: fix Discord badge expired invite code
...
The badge image URL used invite code which is expired,
causing the badge to render 'Invalid invite' instead of the server info.
Updated to use the vanity URL which resolves correctly.
Fixes #313
2026-02-22 20:52:03 -08:00
0xallam and Ahmed Allam
1b7552d3c3
chore(deps): bump google-cloud-aiplatform from 1.129.0 to 1.133.0
...
Bumps [google-cloud-aiplatform](https://github.com/googleapis/python-aiplatform ) from 1.129.0 to 1.133.0.
- [Release notes](https://github.com/googleapis/python-aiplatform/releases )
- [Changelog](https://github.com/googleapis/python-aiplatform/blob/main/CHANGELOG.md )
- [Commits](https://github.com/googleapis/python-aiplatform/compare/v1.129.0...v1.133.0 )
---
updated-dependencies:
- dependency-name: google-cloud-aiplatform
dependency-version: 1.133.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-22 20:51:29 -08:00
0xallam
669d3ebd47
fix: Lower sidebar min width from 140 to 120 for smaller terminals
2026-02-22 09:28:52 -08:00
0xallam
87d41d6823
fix: Update end screen to display models.strix.ai instead of strix.ai and discord
2026-02-22 09:03:56 -08:00
Ahmed Allam and GitHub
b19a08dbd4
Update installation instructions
...
Removed pipx installation instructions for strix-agent.
2026-02-22 00:10:06 +04:00
0xallam
3d2ed12e23
chore: Bump version to 0.8.1
2026-02-20 10:36:48 -08:00
0xallam
d7ad775092
fix: Change default model from claude-sonnet-4-6 to gpt-5 across docs and code
2026-02-20 10:35:58 -08:00
0xallam and Ahmed Allam
dcc40d426e
fix: Handle stray quotes in tag names and enforce parameter tags in prompt
2026-02-20 08:29:01 -08:00
0xallam and Ahmed Allam
3dc42ee78d
fix: Address code review feedback on tool format normalization
2026-02-20 08:29:01 -08:00
0xallam and Ahmed Allam
d2b366a62b
fix: Prevent assistant-message prefill rejected by Claude 4.6
2026-02-20 08:29:01 -08:00
0xallam and Ahmed Allam
88aca80db8
fix: Handle single-quoted and whitespace-padded tool call tags
2026-02-20 08:29:01 -08:00
0xallam and Ahmed Allam
0699fd9fd7
fix: Strip quotes from parameter/function names in tool calls
2026-02-20 08:29:01 -08:00
0xallam and Ahmed Allam
0b69806328
feat: Normalize alternative tool call formats (invoke/function_calls)
2026-02-20 08:29:01 -08:00
Ahmed Allam and GitHub
a773268875
Resolve LLM API Base and Models ( #317 )
2026-02-20 07:14:10 -08:00
0xallam
bbc7cf41a8
fix: Strip custom_llm_provider before cost lookup for proxied models
2026-02-20 06:52:27 -08:00