Block vulnerable changes before merge.
application security
Add Strix security scanning to CI/CD pipelines so pull requests receive diff-scoped vulnerability checks before merging.
When to use it
Use when adding security scanning, SAST/DAST, pentesting, vulnerability checks, or automated security review to a CI pipeline, pre-merge gate, or PR workflow.
Give it a project and a request for CI security scanning; it adds a Strix-based pipeline configuration and merge-gating checks.
What you provide
This skill
GitHub/GitLab/Bitbucket pull requests
Posts PR security findings (irreversible)
Strix cloud scans
Uploads source for cloud review
GitHub code scanning
Uploads SARIF findings
Strix managed repository configuration
Reads repository configuration
The self-hosted scan reads the provider key from the LLM_API_KEY environment variable, together with STRIX_LLM.
Docker must be available on the self-hosted CI runner; this is not needed for the managed platform path.
A Strix managed-platform account and connected source-control app are needed for the managed path; the self-hosted path requires no external account.