--- title: "Introduction" description: "Open-source AI hackers to secure your apps" --- Strix agents are autonomous and act like real hackers. They run your code dynamically, find vulnerabilities, and validate each vulnerability with a proof of concept. Strix helps developers and security teams that need fast and accurate security testing. Strix does not have the overhead of a manual pentest or the false positives of a static analysis tool. Strix Demo Install and run your first scan in minutes. Learn all command-line options. Explore the security testing toolkit. Integrate into your CI/CD pipeline. ## Use Cases - **Application Security Testing:** Detect and validate critical vulnerabilities in your applications - **Rapid Penetration Testing:** Get penetration tests done in hours, not weeks - **Bug Bounty Automation:** Automate research and generate PoCs for faster reporting - **CI/CD Integration:** Block vulnerabilities before they reach production ## Key Capabilities - **Full hacker toolkit:** Browser automation, HTTP proxy, terminal, Python runtime - **Real validation:** PoCs, not false positives - **Multi-agent orchestration:** Specialized agents collaborate on complex targets - **Developer-first CLI:** Interactive TUI or headless mode for automation ## Security Tools Strix agents include a comprehensive toolkit: | Tool | Purpose | |------|---------| | HTTP Proxy | Full request/response manipulation and analysis | | Browser Automation | Multi-tab browser for XSS, CSRF, auth flow testing | | Terminal | Interactive shells for command execution | | Python Runtime | Custom exploit development and validation | | Reconnaissance | Automated OSINT and attack surface mapping | | Code Analysis | Static and dynamic analysis capabilities | ## Vulnerability Coverage | Category | Examples | |----------|----------| | Access Control | IDOR, privilege escalation, auth bypass | | Injection | SQL, NoSQL, command injection | | Server-Side | SSRF, XXE, deserialization | | Client-Side | XSS, prototype pollution, DOM vulnerabilities | | Business Logic | Race conditions, workflow manipulation | | Authentication | JWT vulnerabilities, session management | | Infrastructure | Misconfigurations, exposed services | ## Multi-Agent Architecture Strix uses a graph of specialized agents for comprehensive security testing: - **Distributed Workflows:** Specialized agents for different attacks and assets - **Scalable Testing:** Parallel execution for fast comprehensive coverage - **Dynamic Coordination:** Agents collaborate and share discoveries ## Quick Example ```bash # Install curl -sSL https://strix.ai/install | bash # Configure export STRIX_LLM="openai/gpt-5.4" export LLM_API_KEY="your-api-key" # Scan strix --target ./your-app ``` ## Community Join the community for help and discussion. Star the repo and contribute. Only test applications you own or have explicit permission to test.