Validated findings with proof, not just alerts.
security testing
Pentests authorized web apps, APIs, codebases, repositories, URLs, domains, or IPs and returns validated vulnerabilities with proof-of-concept exploits.
When to use it
Use it when the user asks to pentest, hack, security-scan, security-audit, or find vulnerabilities in an app, API, website, or repository.
Give it a target to pentest; it runs a headless scan and saves validated findings and reports under strix_runs.
What you provide
This skill
the pentest target
Tests the pentest target
Docker sandbox
Scans in Docker
Strix cloud
Uploads source to Strix
Strix cloud scan
Starts managed cloud scans
Docker must be running; the first scan pulls the sandbox image automatically.
The Strix CLI must be installed and available as strix.
The self-hosted CLI reads the provider API key from the LLM_API_KEY environment variable.
An app.strix.ai account is needed for the managed cloud path; the login flow can create one when needed.