Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan.
$ npx skills add usestrix/strix --skill application-security-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install usestrix/strix application-security-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/application-security-testing .claude/skills/application-security-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .claude/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/usestrix/strix/tree/main/skills/application-security-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add usestrix/strix --skill application-security-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install usestrix/strix application-security-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/application-security-testing .agents/skills/application-security-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .agents/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usestrix/strix --skill application-security-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install usestrix/strix application-security-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/application-security-testing .cursor/skills/application-security-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .cursor/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/usestrix/strix.git --path skills/application-security-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add usestrix/strix --skill application-security-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install usestrix/strix application-security-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/application-security-testing .gemini/skills/application-security-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .gemini/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install usestrix/strix application-security-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add usestrix/strix --skill application-security-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/application-security-testing .github/skills/application-security-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .github/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usestrix/strix --skill application-security-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install usestrix/strix application-security-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/application-security-testing .opencode/skills/application-security-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "application-security-testing" agent skill from https://github.com/usestrix/strix/tree/main/skills/application-security-testing into .opencode/skills/application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "application-security-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
application-security-testingRoutes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan.
This is an entry point for a vague request to make an application secure where the target is not yet one URL or repo, and its job is to pick the right test per asset, not to run every test at maximum depth; it points to a separate install skill if the main binary is not working, and to a managed-cloud path for a run with no Docker or local LLM key. It confirms the user is authorized to test each asset first, prefers staging over production since its agents send real exploit payloads, and maps the assets: source repos and languages, running environments, API types and schemas, whether two test accounts in different tenants exist, and constraints such as out-of-scope paths.
A table routes each asset type to a companion skill: a repository to a code-vulnerability skill, a live web app to a web-app pentesting skill, a REST, GraphQL or gRPC API to an API-security skill, an OWASP-mapped assessment to its own skill, every pull request to a CI-scanning skill, and a no-Docker case to a managed-pentesting skill, each carrying its own flags rather than duplicating them here. A suggested first sequence reviews the code, since it is the cheapest run and maps the authorization model, then pentests staging with real credentials while passing the repository as a second target to keep source context.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f1386ca. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Strix Application Security Testing loads about 1.1k tokens when it runs. Until then it costs about 165 tokens; SKILL.md has 541 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from usestrix/strix at commit f1386ca, republished under its Apache-2.0 licence (© usestrix). 541 words, ~1,135 tokens.
.claude/skills/application-security-testing/SKILL.md (or your agent's skills folder).Entry point for "make my application secure" requests, where the target is not yet a single URL or repo. The job here is to pick the right test per asset, run it, and produce one ranked plan — not to run everything at maximum depth.
Install, LLM setup, all CLI flags, and the managed-cloud path live in the penetration-testing-with-strix skill. Read it first if strix --version fails. For a run with no Docker and no LLM key, the same binary drives the managed platform: strix cloud login, then strix cloud scans start ... (details in managed-pentesting-with-strix).
Only test assets the user owns or is authorized to test. Confirm authorization before the first run, and prefer staging over production, because the agents send real exploit payloads and can change data.
Ask (or read from the repo) and write the answers down before scanning:
If there is no staging environment and production is off limits, say so early. A code-only review is still valuable, but it cannot prove exploitability against a live app.
| Asset | Skill to use |
|---|---|
| Repository or working tree | find-security-vulnerabilities-in-code |
| Live web app or staging site | web-app-penetration-testing |
| REST/GraphQL/gRPC API | api-security-testing |
| Assessment mapped to OWASP categories | owasp-top-10-testing |
| Every pull request, continuously | ci-security-scanning-with-strix |
| No Docker, no LLM key, or a report an auditor will accept | managed-pentesting-with-strix |
Those skills carry the flags, credential handling, and result-reading details. Do not duplicate their instructions here.
Sequence for a first assessment:
Run one asset at a time and read each report before starting the next. Findings from the code review make the live run sharper.
Findings arrive per run in strix_runs/<run>/. Merge them into a single list and rank by proven impact, not by scanner severity:
Deduplicate: the same root cause often surfaces in both the code review and the live pentest.
State plainly what was not tested — assets with no staging environment, categories a black-box run cannot reach (logging and alerting, supply-chain integrity, insecure design), and any run that hit its budget or turn cap before finishing. Check run.json status and cost against --max-budget for each run. An empty result set from a truncated scan is not a clean bill of health.
Then remediate with fix-security-vulnerabilities-with-strix, which re-runs Strix against each fix to prove the exploit no longer works.
© usestrix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/application-security-testing of usestrix/strix.
Open the folder on GitHubat commit f1386ca
Strix Application Security Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Strix Application Security Testing this skillusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Myrqenstijnswapped/Myrqen | 137 | — | ~2.1k | Automated safety check: Pass | Custom licence | |
| Gha Security Reviewgetsentry/skills | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | |
| Code Security AuditProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
stijnswapped/Myrqen
Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.
getsentry/skills
GitHub Actions security review for workflow exploitation vulnerabilities.
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
AgentSecOps/SecOpsAgentKit
Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
usestrix/strix
Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.
Categories
Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan. This is an entry point for a vague request to make an application secure where the target is not yet one URL or repo, and its job is to pick the right test per asset, not to run every test at maximum depth; it points to a separate install skill if the main binary is not working, and to a managed-cloud path for a run with no Docker or local LLM key. It confirms the user is authorized to test each asset first, prefers staging over production since its agents send real exploit payloads, and maps the assets: source repos and languages, running environments, API types and schemas, whether two test accounts in different tenants exist, and constraints such as out-of-scope paths.
Strix Application Security Testing fits situations like: starting a security review of a whole product without knowing which test to run first; deciding whether to test source code, a live app, an API or CI; preparing a security assessment ahead of a launch or a customer questionnaire; mapping authorized assets before running any exploit-based test.
Run `npx skills add usestrix/strix --skill application-security-testing -a claude-code`. Or copy the skill folder (skills/application-security-testing in usestrix/strix) into .claude/skills/application-security-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add usestrix/strix --skill application-security-testing -a codex`. Or copy the skill folder (skills/application-security-testing in usestrix/strix) into .agents/skills/application-security-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add usestrix/strix --skill application-security-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/application-security-testing, .gemini/skills/application-security-testing, .github/skills/application-security-testing and .opencode/skills/application-security-testing in your project.
SKILL.md names no scripts, command-line tools or credentials: Strix Application Security Testing is instructions for the agent only. Our summary lists: The strix CLI; Authorization to test the target assets; Docker and an LLM key, or a managed-cloud login as an alternative.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Strix Application Security Testing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Strix Application Security Testing: Code Audit (3stoneBrother/code-audit, 893 stars), Myrqen (stijnswapped/Myrqen, 137 stars), Gha Security Review (getsentry/skills, 1k stars) and Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
usestrix (a GitHub organization) maintains it in usestrix/strix, which has 66,916 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: usestrix/strix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.