Abhiram · AI, Crypto & Tech
← All tools

Strix: open-source AI hackers that test your app before real ones do

You commented SHIELD — here's everything from the video.

Strix is an open-source (Apache-2.0) AI penetration testing tool. A team of AI agents attacks your own app the way a real attacker would, proves each weakness with a working example, and suggests the fix.

Set it up

  1. Get ready

    You need Docker running, and an API key from an AI model provider (OpenAI, Anthropic, Google and others are supported). The model usage is what costs money; Strix itself is free.

  2. Install it

    Run the installer in a terminal.

    curl -sSL https://strix.ai/install | bash
  3. Tell it which AI model to use

    Set the model name and your key. The README lists the supported providers.

    export STRIX_LLM="<provider/model>"
    export LLM_API_KEY="your-api-key"
  4. Run the first test

    Point it at your app's folder. The first run downloads a sandbox image. Results are saved in strix_runs/.

    strix --target ./app-directory
  5. Read the report, fix, run again

    Each finding has a proof and a suggested fix. Fix the serious ones first, then run it again to confirm they are gone.

Good to know

  • Only test apps and servers you own or have written permission to test.
  • It checks for things like broken access control, injection attacks and login bypasses.
  • There is also a paid cloud version; the open-source one runs on your own machine. Facts are from the README on 9 October 2026.

Published 2026-10-09.

Strix: open-source AI hackers that test your app before real ones do