Lightlines
By usestrix

api-security-testing

usestrix

Find API vulnerabilities with reproducible proof.

API security

What it does

Security-tests REST, GraphQL, and gRPC APIs with Strix and returns proof-of-concept requests for discovered vulnerabilities.

When to use it

Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API or backend service.

How to use it

Give it an API target; it runs a security scan and writes reports containing the requests that proved each finding.

What you provide

  • an API target

Uses


Access · 1

This skill

target API

Write

Sends exploit requests to APIs (irreversible)

Good to know

  • starts helper agents, number unstated
  • cannot be undone: target API
  • sends a credential to a server: API credentials/tokens

What you need · 5

The strix CLI must be installed to run either local or managed scans.

Docker enables the local scan path; the managed platform provides an alternative without Docker.

A managed-platform login enables scans without Docker or an LLM key.

Supplied tenant and privilege-level tokens are used against the target API to prove authorization vulnerabilities.


About this skill

Visibility
Public
Repository
usestrix/strix
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
1