{"slug":"strix","name":"Strix","vendor":"Strix","tagline":"Open-source autonomous penetration-testing agents that find, exploit and help fix vulnerabilities in your app","url":"https://agentboards.org/agent/strix","website":"https://strix.ai","docs":"https://docs.strix.ai","repo":"https://github.com/usestrix/strix","category":"harness","execution":["local","cloud","sandbox"],"license":"Apache-2.0","open_source":true,"pricing":{"model":"mixed","summary":"Open-source CLI is free with your own model keys; the cloud platform at app.strix.ai has a free tier, paid plans and enterprise deployments","from_usd":0,"free_tier":true,"byok":true},"models":{"backbone":["GLM","GPT","Claude","Gemini","DeepSeek","Kimi","Ollama","LM Studio"],"bring_your_own_model":true,"local_models":true},"protocols":{"mcp_client":true,"mcp_server":false,"openapi":false},"capabilities":{"terminal_exec":true,"browser":true,"multi_file_edit":false,"git_ops":false,"docker_sandbox":true,"multi_agent":true,"headless_ci":true},"context_window":null,"platforms":["macos","linux"],"install":[{"label":"curl","command":"curl -sSL https://strix.ai/install | bash"}],"benchmarks":[],"tags":["open-source","security","pentest","autonomous","sandbox","multi-agent","mcp","ci"],"github_stars":65976,"metrics":{"stars":65976,"pushed_at":"2026-10-02T03:23:13Z","archived":false,"open_issues":436,"latest_version":"v1.6.2","latest_version_at":"2026-09-05T01:30:11Z","latest_version_url":"https://github.com/usestrix/strix/releases/tag/v1.6.2","version_source":"github","checked_at":"2026-10-02T05:02:45.004Z"},"sources":{"readme":"https://github.com/usestrix/strix","install":"https://github.com/usestrix/strix","capabilities":"https://docs.strix.ai/usage/cli.md","models":"https://docs.strix.ai/llm-providers/local.md","protocols":"https://docs.strix.ai/integrations/mcp.md"},"verified_at":null,"adoption":{"score":7.8,"signals":{"github_stars":65059,"hn_mentions_1y":59},"measured_at":"2026-09-28"},"scores":{"panel":6.9,"adoption":7.8,"spread":1.3,"facts":4.7,"board":6.7,"dimensions":{"reliability":6.3,"usefulness":7.5,"cost":6.5,"longevity":7.2},"per_persona":{"amigo":7,"critico":6.3,"profesor":6.8,"inversora":7.5,"jefa":6.3,"hacker":7.5},"community":null},"rank":null,"category_rank":12,"panel_reviews":[{"persona":"juez","persona_name":"El Juez","ai_generated":true,"verdict":"Narrow spread, but El Crítico and La Jefa both price legal scope while La Inversora prices the SOC 2 logo wall; the split is about permission, not capability.","scores":null,"evidence":[]},{"persona":"amigo","persona_name":"El Amigo","ai_generated":true,"verdict":"Pick Strix if you own an application and want a working exploit before the auditor finds one; pick CodeRabbit or Greptile if what you need is review, not a break-in.","scores":{"reliability":6,"usefulness":8,"cost":7,"longevity":7},"evidence":["https://strix.ai","https://github.com/usestrix/strix"]},{"persona":"critico","persona_name":"El Crítico","ai_generated":true,"verdict":"It sells working proofs of concept, not false positives, without publishing a false-positive rate, and it attacks from a README that reminds you unauthorised testing is illegal.","scores":{"reliability":5,"usefulness":7,"cost":6,"longevity":7},"evidence":["https://github.com/usestrix/strix","https://docs.strix.ai"]},{"persona":"profesor","persona_name":"El Profesor","ai_generated":true,"verdict":"A graph of specialised agents for reconnaissance, exploitation and post-exploitation that share discoveries in parallel; verification is execution, since a finding counts only when the exploit runs.","scores":{"reliability":7,"usefulness":7,"cost":6,"longevity":7},"evidence":["https://docs.strix.ai","https://github.com/usestrix/strix"]},{"persona":"inversora","persona_name":"La Inversora","ai_generated":true,"verdict":"SOC 2 Type II, ISO 27001 and a logo wall with AWS, PayPal, Uber, Ford and Pfizer: a security company that sells the way security companies sell, references first.","scores":{"reliability":7,"usefulness":8,"cost":7,"longevity":8},"evidence":["https://strix.ai","https://github.com/usestrix/strix"]},{"persona":"jefa","persona_name":"La Jefa","ai_generated":true,"verdict":"A GitHub Actions workflow runs a quick scan on every pull request with one command, the enterprise tier is self-hosted with a Slack channel and SLAs, and the price is a conversation.","scores":{"reliability":6,"usefulness":7,"cost":5,"longevity":7},"evidence":["https://strix.ai","https://github.com/usestrix/strix"]},{"persona":"hacker","persona_name":"El Hacker","ai_generated":true,"verdict":"Apache-2.0, STRIX_LLM plus LLM_API_BASE to point it at a local endpoint, a default of openrouter/z-ai/glm-5.3, and MCP servers in ~/.strix/mcp-servers.json with per-tool filtering.","scores":{"reliability":7,"usefulness":8,"cost":8,"longevity":7},"evidence":["https://github.com/usestrix/strix","https://docs.strix.ai"]},{"persona":"comediante","persona_name":"El Comediante","ai_generated":true,"verdict":"A security tool whose install instructions begin with curl piped to bash, which is either irony or the first test.","scores":null,"evidence":[]}]}