Find API vulnerabilities with reproducible proof.
API security
Security-tests REST, GraphQL, and gRPC APIs with Strix and returns proof-of-concept requests for discovered vulnerabilities.
When to use it
Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API or backend service.
Give it an API target; it runs a security scan and writes reports containing the requests that proved each finding.
What you provide
This skill
target API
Sends exploit requests to APIs (irreversible)
The strix CLI must be installed to run either local or managed scans.
Docker enables the local scan path; the managed platform provides an alternative without Docker.
A managed-platform login enables scans without Docker or an LLM key.
Supplied tenant and privilege-level tokens are used against the target API to prove authorization vulnerabilities.