mirror of
https://github.com/usestrix/strix.git
synced 2026-08-17 01:29:42 +02:00
64 lines
3.7 KiB
Plaintext
64 lines
3.7 KiB
Plaintext
---
|
|
title: "Coding Agents"
|
|
description: "Use Strix from Claude Code, Cursor, Codex, and other AI agents"
|
|
---
|
|
|
|
Strix is built to be driven by AI coding agents. Install the official agent skills and your agent knows how to run pentests, remediate findings, and wire Strix into CI.
|
|
|
|
## Install the Skills
|
|
|
|
Works with any agent that supports the open [SKILL.md standard](https://agentskills.io), including Claude Code, Cursor, Codex, Gemini CLI, OpenCode, and dozens more:
|
|
|
|
```bash
|
|
npx skills add usestrix/strix
|
|
```
|
|
|
|
| Skill | What your agent learns |
|
|
|-------|------------------------|
|
|
| `penetration-testing-with-strix` | Run headless scans against code, URLs, domains, or IPs with the self-hosted CLI or the managed cloud, apply budget caps, and read the results |
|
|
| `managed-pentesting-with-strix` | Drive the managed [app.strix.ai](https://app.strix.ai) platform over REST. No local Docker or LLM key needed |
|
|
| `fix-security-vulnerabilities-with-strix` | Triage findings, fix root causes, and re-run Strix to verify each fix |
|
|
| `ci-security-scanning-with-strix` | Add PR security scanning to GitHub Actions or any CI (self-hosted CLI or managed app) |
|
|
|
|
Install a single skill with `npx skills add usestrix/strix --skill penetration-testing-with-strix`, or use one without installing:
|
|
|
|
```bash
|
|
npx skills use usestrix/strix@penetration-testing-with-strix | claude
|
|
```
|
|
|
|
## Two ways to run: self-hosted or managed
|
|
|
|
Both use the same engine and produce the same validated findings and SARIF. Agents can pick per situation or combine them.
|
|
|
|
- **Open-source CLI (self-hosted):** Runs locally in a Docker sandbox with your own LLM key. It is free, fully local, and air-gap capable. It suits local development loops and full control.
|
|
- **Managed cloud:** Runs on Strix infrastructure through the [app.strix.ai REST API](https://docs.app.strix.ai). It needs no Docker, LLM key, or local installation. The Enterprise plan adds team dashboards, scheduling, pull request reviews, and downloadable PDF or DOCX reports. It suits sandboxed or CI environments and teams.
|
|
|
|
Create a managed API token under **Settings → API Access**. The `managed-pentesting-with-strix` skill documents the full flow.
|
|
|
|
## Agent-Friendly Interfaces
|
|
|
|
Everything an agent needs is machine-readable:
|
|
|
|
- **Headless CLI:** `strix -n` runs without the TUI. It exits with `0` for a clean scan, `1` for an error, or `2` for vulnerabilities.
|
|
- **REST API:** The managed platform exposes a documented [OpenAPI](https://docs.app.strix.ai/openapi.json) at `https://app.strix.ai/api/v1`. It supports scans, vulnerabilities, assets, pull request reviews, schedules, and webhooks. The API uses bearer tokens and scopes.
|
|
- **Structured results:** Each self-hosted run writes `vulnerabilities.json`, `vulnerabilities.csv`, and `findings.sarif` in SARIF 2.1.0 format. It also writes per-finding Markdown under `strix_runs/<run-name>/`. The cloud exposes the same data as JSON and provides SARIF export.
|
|
- **Budget controls:** `--max-budget` and `--max-turns` set cost and turn limits.
|
|
- **`AGENTS.md`:** The [repository's agent guide](https://github.com/usestrix/strix/blob/main/AGENTS.md) provides a quick reference.
|
|
- **`llms.txt`:** The index is available at [docs.strix.ai/llms.txt](https://docs.strix.ai/llms.txt). The full export is available at [docs.strix.ai/llms-full.txt](https://docs.strix.ai/llms-full.txt). Every page is also available as Markdown by appending `.md` to its URL.
|
|
|
|
## Example Prompts
|
|
|
|
Once the skills are installed, prompts like these just work:
|
|
|
|
```text
|
|
Pentest this repo with Strix (quick mode, $10 budget) and summarize the findings.
|
|
```
|
|
|
|
```text
|
|
Fix all critical and high findings from the last Strix run, then re-scan to verify.
|
|
```
|
|
|
|
```text
|
|
Add Strix security scanning to our GitHub Actions so every PR gets tested.
|
|
```
|