usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
About the project
Open-source AI pentesting tool: autonomous agents run your code, find vulnerabilities, and validate them with working PoCs. For developers and security teams needing fast testing without manual pentests or static-analysis false positives.
Useful for
- Run a pentest of a local app directory via CLI with Docker and your own LLM key
- Add vulnerability scanning to GitHub Actions and block insecure code in pull requests
- Automate bug bounty research by finding vulnerabilities and generating PoCs for reports
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 49 stars so far today, about 133 expected by the end of the day.
- GitHub Trending Python today: #14, +208 stars.
- About 23 forks a day — people are taking the code.
- Recent forks include notable developers: @h4x0r-dz (861 followers).
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 64,920
- Today
- 49 · ≈ 133 by evening
- Forks
- 7,114
- Issues and pull requests
- 1,322
- Watchers
- 290
- Language
- Python
- License
- Apache-2.0
- Latest release
- v1.6.2 · September 5, 2026
- Created
- August 5, 2025
- Last push
- September 25, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 26, 2026GitHub Trending Python today: #14, +208 stars
Similar by description
-
1.4
openai/codex-security
OpenAI's CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in code, and for drafting SECURITY.md security policy.
-
2.3
Armur-Ai/Pentest-Swarm-AI
Open-source XBOW alternative: an autonomous API and web-app pentester where dozens of AI agents run recon, exploitation, and reporting in parallel via a shared blackboard. For pentesters, bug bounty hunters, and red…
-
2.2
projectdiscovery/nuclei
A vulnerability scanner driven by YAML templates that checks applications, APIs, networks, DNS and cloud configurations for known vulnerabilities. Community-contributed templates mimic real-world exploitation steps to…