Get a short list of exploit-validated code vulnerabilities.
code security
Finds exploitable security vulnerabilities in source code and reports them with working proofs of concept.
When to use it
Use when asked to scan, review, or audit a codebase, repository, or pull request for security vulnerabilities.
Give it a code project; it writes a penetration-test report and detailed vulnerability findings under strix_runs.
What you provide
This skill
running instance of the app
Sends exploit attempts to your app
The strix command must be available to run the security review.
A running application instance is optional and enables validation against live behavior instead of static reasoning alone.
Routes diff-scoped branch or pull-request review, merge blocking, comments, and SARIF upload to this skill.