Install the Skills
Works with any agent that supports the open SKILL.md standard — Claude Code, Cursor, Codex, Gemini CLI, OpenCode, and dozens more:
Install a single skill with
npx skills add usestrix/strix --skill penetration-testing-with-strix, or use one without installing:
Two ways to run — self-hosted or managed
Both use the same engine and produce the same validated findings and SARIF, so agents can pick per situation or combine them:- Open-source CLI (self-hosted) — runs locally in a Docker sandbox with your own LLM key. Free, fully local, air-gap capable. Best for local dev loops and full control.
- Managed cloud — runs on Strix’s infrastructure. Drive it with the
strix cloudCLI (every REST operation has astrix cloud <resource> <verb>command) or the app.strix.ai REST API directly. No Docker, no LLM key; adds team dashboards, scheduling, PR reviews, and downloadable PDF/DOCX reports (Enterprise plan). Best in sandboxed/CI environments and for teams. Sign in withstrix cloud login(browser device sign-in, account created on first use) or create a token in the dashboard under Settings → API Access. Themanaged-pentesting-with-strixskill has the full flow.
Agent-Friendly Interfaces
Everything an agent needs is machine-readable:- Headless CLI —
strix -nruns without the TUI and exits with0(clean),1(error), or2(vulnerabilities found). - Cloud CLI —
strix cloudprints JSON when stdout is not a terminal (or with--json), never prompts without a TTY, and exits with0(success),1(error),2(usage),4(authentication required), or5(payment required). Credit top-ups pay the Stripe machine-payment challenge with an agent wallet (strix cloud billing topup --credits N --yes). Account setup also runs from the CLI:strix cloud workspaces list|create|use,strix cloud org members invite,strix cloud billing subscribe,strix cloud billing portal, andstrix cloud integrations install github. The last three print a hosted link the user opens to finish the payment or approve the installation. - REST API — the managed platform exposes a documented OpenAPI at
https://app.strix.ai/api/v1(scans, vulnerabilities, assets, PR reviews, schedules, webhooks) with bearer tokens and scopes. - Structured results — every run writes
vulnerabilities.json,vulnerabilities.csv,findings.sarif(SARIF 2.1.0), and per-finding Markdown understrix_runs/<run-name>/; the cloud exposes the same as JSON plus SARIF export. - Budget controls —
--max-budgetand--max-turnsgive agents hard cost/time caps. AGENTS.md— the repository’s agent guide with a quick reference.llms.txt— this documentation is indexed at docs.strix.ai/llms.txt and fully exported at docs.strix.ai/llms-full.txt; every page is also available as Markdown by appending.mdto its URL.