Lightlines
By usestrix

penetration-testing-with-strix

usestrix

Validated findings with proof, not just alerts.

security testing

What it does

Pentests authorized web apps, APIs, codebases, repositories, URLs, domains, or IPs and returns validated vulnerabilities with proof-of-concept exploits.

When to use it

Use it when the user asks to pentest, hack, security-scan, security-audit, or find vulnerabilities in an app, API, website, or repository.

How to use it

Give it a target to pentest; it runs a headless scan and saves validated findings and reports under strix_runs.

What you provide

  • target URL, domain, IP, or repository
  • An existing project

Uses


Access · 4

This skill

the pentest target

Read

Tests the pentest target

Docker sandbox

Execute

Scans in Docker

Strix cloud

Write

Uploads source to Strix

Strix cloud scan

Execute

Starts managed cloud scans

What you need · 4

Docker must be running; the first scan pulls the sandbox image automatically.

The Strix CLI must be installed and available as strix.

The self-hosted CLI reads the provider API key from the LLM_API_KEY environment variable.

An app.strix.ai account is needed for the managed cloud path; the login flow can create one when needed.


About this skill

Visibility
Public
Repository
usestrix/strix
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
1