Strix: open-source AI hackers that test your app before real ones do
You commented SHIELD — here's everything from the video.
Strix is an open-source (Apache-2.0) AI penetration testing tool. A team of AI agents attacks your own app the way a real attacker would, proves each weakness with a working example, and suggests the fix.
Set it up
- Get ready
You need Docker running, and an API key from an AI model provider (OpenAI, Anthropic, Google and others are supported). The model usage is what costs money; Strix itself is free.
- Install it
Run the installer in a terminal.
curl -sSL https://strix.ai/install | bash - Tell it which AI model to use
Set the model name and your key. The README lists the supported providers.
export STRIX_LLM="<provider/model>" export LLM_API_KEY="your-api-key" - Run the first test
Point it at your app's folder. The first run downloads a sandbox image. Results are saved in strix_runs/.
strix --target ./app-directory - Read the report, fix, run again
Each finding has a proof and a suggested fix. Fix the serious ones first, then run it again to confirm they are gone.
Good to know
- Only test apps and servers you own or have written permission to test.
- It checks for things like broken access control, injection attacks and login bypasses.
- There is also a paid cloud version; the open-source one runs on your own machine. Facts are from the README on 9 October 2026.
One free AI tool, every day
Follow so the next one reaches you.
Published 2026-10-09.
