Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-code --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .claude/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .claude/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-codeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-code --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .agents/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .agents/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-code --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .cursor/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .cursor/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/usestrix/strix.git --path skills/find-security-vulnerabilities-in-code--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-code --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .gemini/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .gemini/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-codeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .github/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .github/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install usestrix/strix find-security-vulnerabilities-in-code --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/find-security-vulnerabilities-in-code .opencode/skills/find-security-vulnerabilities-in-code && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "find-security-vulnerabilities-in-code" agent skill from https://github.com/usestrix/strix/tree/main/skills/find-security-vulnerabilities-in-code into .opencode/skills/find-security-vulnerabilities-in-code/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-security-vulnerabilities-in-code", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
find-security-vulnerabilities-in-codeRuns a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
The agent uses the strix command to build a model of routes, sinks and authorization checks from the source and then attempts real exploitation, so the output is a short list of proven issues rather than a long list of potential pattern-matching hits. It covers injection, XSS, SSRF, broken access control and IDOR, insecure deserialization, secrets in code, unsafe dependencies and business-logic flaws.
A typical run points at the local working tree with a scan mode and a budget. Two things improve results: adding a running instance of the app as a second target, so exploitability is confirmed against live behavior (static-only findings should be called unconfirmed), and scoping the review to the risky subtree with an instruction describing the tenancy model, trust boundaries and attacker-controlled inputs. A local path is mounted into the sandbox as writable, so run it on a clean checkout.
Results land in strix_runs, starting with penetration_test_report.md, with one markdown file per vulnerability, JSON and CSV lists and a findings.sarif file for GitHub code scanning. Before reporting, the agent checks that each proof-of-concept shows real impact and cites the file and line. Install, LLM setup, the managed cloud path and diff-scoped pull request scanning in CI are covered by sibling skills.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f1386ca. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Strix Code Vulnerability Scan loads about 1.1k tokens when it runs. Until then it costs about 160 tokens; SKILL.md has 409 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from usestrix/strix at commit f1386ca, republished under its Apache-2.0 licence (© usestrix). 409 words, ~1,094 tokens.
.claude/skills/find-security-vulnerabilities-in-code/SKILL.md (or your agent's skills folder).White-box security review with Strix: the agents read the source to build a model of routes, sinks, and authorization checks, then attempt real exploitation. Findings come with a proof-of-concept, so the output is a short list of proven issues rather than the hundreds of "potential" hits a pattern-matching scanner produces.
Install, LLM setup, all flags, and the managed-cloud path are in the penetration-testing-with-strix skill. For a run with no Docker and no LLM key, the same binary drives the managed platform: strix cloud login, then strix cloud scans start ... (details in managed-pentesting-with-strix).
# Local working tree
strix -n -t ./ --scan-mode standard --max-budget 15
# A GitHub repo directly
strix -n -t https://github.com/org/app --max-budget 15
# Monorepo: point at the service that matters, not the whole tree
strix -n -t ./services/checkout --max-budget 20
# Only what a branch changed (whole-repo review is wasteful on a large repo)
strix -n -t ./ --scope-mode diff --diff-base origin/main --max-budget 10A local path is mounted into the sandbox writable, so the agents can modify it. Run against a clean checkout.
Two things sharply improve results:
-t ./ -t http://host.docker.internal:3000 lets the agents confirm exploitability against live behavior instead of reasoning about it statically — this is the difference between "this looks unsafe" and a validated finding. If nothing is running, static-only findings should be described as unconfirmed.strix -n -t ./services/api --max-budget 15 \
--instruction "Focus on the authorization layer in src/auth and every route under src/routes/admin. Multi-tenant app: tenant id comes from the JWT. Flag any query that filters by object id without also filtering by tenant."For diff-scoped review of a branch or PR (and blocking merges on findings), use ci-security-scanning-with-strix — it covers diff scoping, PR comments, and SARIF upload to GitHub code scanning. The managed platform can also review PRs directly via API (managed-pentesting-with-strix).
In strix_runs/<run>/: penetration_test_report.md (start here), vulnerabilities/*.md (one per finding, with PoC and remediation), vulnerabilities.json / .csv, findings.sarif (upload to code scanning), run.json.
Before reporting to the user, open each finding and check the PoC actually demonstrates impact. Report file and line alongside the exploit so the fix is obvious.
Exit 0 means nothing exploitable was proven in what was analyzed — not that the codebase is clean. Check run.json status and cost against --max-budget, and note which paths went unreviewed if the run was capped.
This is exploit-validated review, not an exhaustive inventory. Keep a dependency scanner (SCA) and secret scanning in place for complete coverage of known-CVE dependencies and committed credentials; use this for the logic, authorization, and injection bugs those tools structurally cannot find.
Hand results to fix-security-vulnerabilities-with-strix: patch the root cause (the shared authorization helper, not the one route), then re-run Strix to prove the exploit no longer works.
© usestrix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/find-security-vulnerabilities-in-code of usestrix/strix.
Open the folder on GitHubat commit f1386ca
Strix Code Vulnerability Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Strix Code Vulnerability Scan this skillusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Security Checkgocronx-team/gocron | 808 | — | ~690 | Automated safety check: Pass | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Sentry Securitygetsentry/sentry | 45k | — | ~2.3k | Automated safety check: Notes | Custom licence |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
gocronx-team/gocron
Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
getsentry/sentry
Sentry-specific security review based on real vulnerability history.
zebbern/claude-code-guide
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
usestrix/strix
Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.
usestrix/strix
Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan.
Works with
Categories
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. The agent uses the strix command to build a model of routes, sinks and authorization checks from the source and then attempts real exploitation, so the output is a short list of proven issues rather than a long list of potential pattern-matching hits. It covers injection, XSS, SSRF, broken access control and IDOR, insecure deserialization, secrets in code, unsafe dependencies and business-logic flaws.
Strix Code Vulnerability Scan fits situations like: security-reviewing a repository before a release; auditing an app for broken access control or IDOR in its API; confirming that a suspected vulnerability is actually exploitable; scanning a codebase for secrets and unsafe dependencies.
Run `npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a claude-code`. Or copy the skill folder (skills/find-security-vulnerabilities-in-code in usestrix/strix) into .claude/skills/find-security-vulnerabilities-in-code in your project. Claude Code loads it when a task matches its description.
Run `npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a codex`. Or copy the skill folder (skills/find-security-vulnerabilities-in-code in usestrix/strix) into .agents/skills/find-security-vulnerabilities-in-code in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add usestrix/strix --skill find-security-vulnerabilities-in-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-security-vulnerabilities-in-code, .gemini/skills/find-security-vulnerabilities-in-code, .github/skills/find-security-vulnerabilities-in-code and .opencode/skills/find-security-vulnerabilities-in-code in your project.
SKILL.md names no scripts, command-line tools or credentials: Strix Code Vulnerability Scan is instructions for the agent only. Our summary lists: The strix CLI; Docker for the local sandbox; An LLM API key, or a managed cloud login.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Strix Code Vulnerability Scan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Strix Code Vulnerability Scan: Code Audit (3stoneBrother/code-audit, 893 stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Check (gocronx-team/gocron, 808 stars) and Cyber Neo (Hainrixz/cyber-neo, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
usestrix (a GitHub organization) maintains it in usestrix/strix, which has 66,916 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: usestrix/strix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.