Strix is an open-source AI penetration testing tool published on GitHub. It uses autonomous AI penetration testing agents that run code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept, rather than relying on static analysis. The project describes itself as an open-source AI pentesting tool whose autonomous AI hackers find and fix an application's vulnerabilities. The tool ships with a full pentesting toolkit covering reconnaissance, exploitation, and validation, along with multi-agent orchestration in which teams of AI pentesters collaborate and scale. Other stated capabilities include real exploit validation with working proofs-of-concept, a developer-first CLI with remediation guidance, and auto-fix and reporting that generates patches and compliance-ready pentest reports. The stated audience is developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools. Strix can be run in several ways: as open source software that runs locally with Docker and the user's own LLM key, through Strix Cloud, or as an Enterprise deployment with SSO, compliance-ready reports, and VPC or self-hosted options. Scans write results to disk under strix_runs/<run-name> and can be opened in a local web viewer with the strix view command. The CLI also supports a headless, non-interactive mode for servers and automated jobs, and can be added to CI/CD pipelines such as GitHub Actions.

Security teams use Strix for application security testing to detect and validate critical vulnerabilities in their applications.
Teams use Strix for rapid penetration testing to complete penetration tests in hours rather than weeks, with compliance reports.
Bug bounty researchers use Strix to automate bug bounty research and generate PoCs for faster reporting.
Development teams use Strix in CI/CD to block vulnerabilities before they reach production.
Teams use Strix to run a security review of a GitHub repository by pointing the CLI at the repository URL.
Teams use Strix to test every declared endpoint of an API by pointing it at an OpenAPI, Swagger, or Postman contract.
Teams use Strix for grey-box authenticated testing by supplying credentials through an instruction.
Teams use Strix in headless mode to run scans programmatically on servers and automated jobs.
Download DeskClaw — the easiest way to run OpenClaw AI agent on your desktop. No terminal, no config. Works on Windows & macOS. Free to start.
✨ Zero-config AI chat assistant. No API key needed — sign up and instantly chat with GPT-5, Claude 4, Gemini 2.5, DeepSeek & 100+ top models. Pay-as-you-go saves you more. Available on Web, iOS, macOS, Android, Linux, Windows. - ChatGPTNextWeb/NextChat
Discover Lorka, a multi-AI tool to combine GPT, Gemini, DeepSeek, and more in a single subscription. Fast, flexible, all-in-one AI.
Official website restored from the pre-incident audit; product details pending editorial verification.