Agent skill

Fix Strix Security Findings

by usestrix in usestrix/strix

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

Apache-2.0Auto-check passedSecurity

Install Fix Strix Security Findings

skills CLI
$ npx skills add usestrix/strix --skill fix-security-vulnerabilities-with-strix -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install usestrix/strix fix-security-vulnerabilities-with-strix --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/usestrix/strix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fix-security-vulnerabilities-with-strix .claude/skills/fix-security-vulnerabilities-with-strix && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-security-vulnerabilities-with-strix
GitHub stars
67k
Token cost
~1.5k tokens
SKILL.md length
513 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

  • Works in 4 steps: Triage → Fix → Verify by re-running Strix → …
  • A Strix scan has reported findings that need patching
  • SKILL.md covers 1. Triage, 2. Fix, 3. Verify by re-running Strix and 4. Report
  • Calls git, jq and curl

What it does

Findings come either from the open-source CLI's `strix_runs` output, where each finding has its own markdown file and a combined `vulnerabilities.json`, or from the Strix cloud through `strix cloud vulns list` and `strix cloud scans get`. Work goes from critical down to low. Every Strix finding was validated with a working proof of concept, so the agent must re-test the PoC before dismissing one as a false positive.

For each finding the agent reproduces the issue, fixes the root cause rather than the specific payload, such as parameterizing queries or enforcing authorization in the handler, and prefers the framework's built-in defenses over ad-hoc sanitizing. Expected fixes are listed per class: injection, IDOR, SSRF, XSS, exposed secrets and client-side auth checks. It then re-scans the fixed area to confirm the finding is gone, and cloud findings can be marked fixed with `strix cloud vulns update`.

When your agent uses it

  • A Strix scan has reported findings that need patching
  • Working through vulnerabilities.json or findings.sarif from a pentest
  • Proving a fix works by re-running Strix on the affected area
  • Remediating injection, XSS, SSRF or IDOR findings

Example prompts

  • “Fix the critical and high findings in the latest strix_runs report, then re-scan to confirm.”
  • “Pull the findings from my cloud Strix scan, patch the IDOR issue and mark it fixed once verified.”
  • “Go through findings.sarif and patch the SSRF finding at the root instead of blocking the payload.”

Requirements

  • The Strix CLI and a completed scan with findings
  • A Strix cloud login when working from cloud scans

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Triage
  2. Fix
  3. Verify by re-running Strix
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit f1386ca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • jq
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Strix Security Findings loads about 1.5k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 513 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from usestrix/strix at commit f1386ca, republished under its Apache-2.0 licence (© usestrix). 513 words, ~1,490 tokens.

Download SKILL.mdSave it as .claude/skills/fix-security-vulnerabilities-with-strix/SKILL.md (or your agent's skills folder).
name
fix-security-vulnerabilities-with-strix
description
Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use after a Strix scan reports findings, or when the user asks to remediate, patch, or fix security issues from a strix_runs report, vulnerabilities.json, findings.sarif, or a cloud scan.
license
Apache-2.0
metadata.author
usestrix
metadata.homepage
https://docs.strix.ai

Fix Strix findings and verify

Turn validated Strix findings into minimal, correct fixes — and prove they work by re-scanning.

1. Triage

Get the findings from wherever the scan ran:

  • OSS CLI — artifacts in strix_runs/<run-name>/:
    • vulnerabilities/*.md — one finding per file: description, severity, PoC steps or script, affected code locations, remediation guidance.
    • vulnerabilities.json — the same findings as JSON (ids, severity, CWE/CVE, code_locations with fix_before/fix_after suggestions when available).
  • Cloud (app.strix.ai) — pull findings with the CLI: strix cloud vulns list --scan-id <scan-id> --json (or strix cloud scans get <scan-id> --json | jq '.vulnerabilities', or strix cloud vulns list --severity critical org-wide). Each finding carries severity, cwe, endpoint, method, impact, technical_analysis, poc_description, poc_script_code and, for code findings, code_file/code_diff/code_before/code_after. After a fix is verified, mark it with strix cloud vulns update <id> --status fixed. See the managed-pentesting-with-strix skill for strix cloud login and scopes.

Order work by severity: critical → high → medium → low. Every Strix finding was validated with a working proof-of-concept, so do not dismiss findings as false positives without re-testing the PoC yourself.

2. Fix

For each finding:

  1. Reproduce it with the PoC from the finding file when feasible.
  2. Fix the root cause, not the specific payload (parameterize every query instead of blocking one string, and enforce authorization in the handler instead of hiding the endpoint).
  3. Prefer the framework's built-in defense (ORM parameterization, template auto-escaping, CSRF middleware, centralized authz) over ad-hoc sanitization.
  4. Keep the diff minimal and apply the repo's existing patterns. Finding files often include fix_before/fix_after snippets — use them as a starting point, not verbatim.

Common finding classes and expected fixes: injection → parameterization/escaping at the sink; IDOR/broken access control → object-level authorization checks; SSRF → allowlist + block internal ranges; XSS → context-aware output encoding + CSP; secrets exposure → rotate the secret AND remove it from code/history; auth issues → fix the server-side check (never client-side).

Show full SKILL.md (214 more words)Show less

3. Verify by re-running Strix

After fixing, re-scan scoped to the fixed area and confirm the finding is gone. Verify in whichever environment you scanned (or both):

OSS CLI:

bash
# Re-test just the changed files (fast). Resolve the repo's real default
# branch instead of assuming origin/main (many repos use master/develop).
# Avoid the current branch's own upstream as the base — its merge base with
# HEAD would be HEAD, giving an empty diff and a falsely clean result.
DIFF_BASE=$(git symbolic-ref --quiet --short refs/remotes/origin/HEAD 2>/dev/null)
# origin/HEAD can be a dangling symbolic ref — keep it only if its target exists.
git rev-parse --verify --quiet "$DIFF_BASE" >/dev/null 2>&1 || DIFF_BASE=""
if [ -z "$DIFF_BASE" ]; then
  for b in origin/main origin/master origin/develop; do
    git rev-parse --verify --quiet "$b" >/dev/null && DIFF_BASE="$b" && break
  done
fi
# No silent fallback: a guess like HEAD~1 would cover only the last commit of a
# multi-commit fix branch. If no base resolves, ask the user for the base branch
# (or use the focused --instruction verification below, which needs no diff base).
[ -n "$DIFF_BASE" ] || { echo "Set DIFF_BASE to the branch your fix will merge into." >&2; exit 1; }
strix -n -t ./ --scan-mode quick --scope-mode diff --diff-base "$DIFF_BASE" --max-budget 5

# Or re-test with the original finding as focus (no diff base needed)
strix -n -t ./ --instruction "Verify the SQL injection in app/api/search.py is fixed. Original PoC: <poc>" --max-budget 5

Exit codes: 2 = findings remain (read the new strix_runs/<run>/vulnerabilities/ and iterate); 0 = clean for what was analyzed. Before trusting a 0, confirm the run wasn't cut short — check run.json for a completed status and compare its llm_usage.cost with --max-budget: a hard budget stop leaves status: "stopped", but a run that wrapped up on a budget warning records "completed" with partial coverage. Give verification enough budget to finish, and prefer re-running the specific PoC as the ground-truth signal.

Cloud: rerun with the same config and re-poll, then confirm the finding no longer appears:

bash
new_id=$(curl -sS "$BASE/scans/$scan_id/rerun" "${auth[@]}" -X POST | jq -r .scan_id)
# poll GET /scans/$new_id until completed, then check its vulnerabilities[]

Or, if the cloud scan came from a repo/PR, trigger a fresh PR review on the fix branch (POST /pr-reviews/start). The platform also retests a single finding directly: POST /api/v1/vulnerabilities/{vulnerabilityId}/retest.

  • Also re-run the PoC manually when it is a simple request/script — fastest signal.
  • Run the project's own test suite to make sure the fix does not break behavior.

4. Report

Summarize per finding: severity, root cause, fix applied (file:line), verification result (re-scan clean / PoC no longer reproduces). Never include live secrets in the report; if a secret leaked, state that rotation is required.

© usestrix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/fix-security-vulnerabilities-with-strix of usestrix/strix.

Open the folder on GitHubat commit f1386ca

Compare with similar skills

Fix Strix Security Findings next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Strix Security Findings compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Strix Security Findings this skillusestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Security and Hardeningaddyosmani/agent-skills102k1 repos~4.4kAutomated safety check: NotesMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    102k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    133 GitHub stars~3.1k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.6k GitHub starsUsed in 7 repos~3.1k tokens
    SecurityAuto-check passed

More from usestrix/strix

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

    67k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan.

    67k GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Fix Strix Security Findings

What does Fix Strix Security Findings do?

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. json`, or from the Strix cloud through `strix cloud vulns list` and `strix cloud scans get`. Work goes from critical down to low.

When should I use Fix Strix Security Findings?

Fix Strix Security Findings fits situations like: A Strix scan has reported findings that need patching; working through vulnerabilities.json or findings.sarif from a pentest; proving a fix works by re-running Strix on the affected area; remediating injection, XSS, SSRF or IDOR findings.

How do I install Fix Strix Security Findings in Claude Code?

Run `npx skills add usestrix/strix --skill fix-security-vulnerabilities-with-strix -a claude-code`. Or copy the skill folder (skills/fix-security-vulnerabilities-with-strix in usestrix/strix) into .claude/skills/fix-security-vulnerabilities-with-strix in your project. Claude Code loads it when a task matches its description.

How do I install Fix Strix Security Findings in Codex?

Run `npx skills add usestrix/strix --skill fix-security-vulnerabilities-with-strix -a codex`. Or copy the skill folder (skills/fix-security-vulnerabilities-with-strix in usestrix/strix) into .agents/skills/fix-security-vulnerabilities-with-strix in your project. Codex loads it when a task matches its description.

Can I use Fix Strix Security Findings in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add usestrix/strix --skill fix-security-vulnerabilities-with-strix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-vulnerabilities-with-strix, .gemini/skills/fix-security-vulnerabilities-with-strix, .github/skills/fix-security-vulnerabilities-with-strix and .opencode/skills/fix-security-vulnerabilities-with-strix in your project.

What does Fix Strix Security Findings need to run?

Going by SKILL.md and its folder, Fix Strix Security Findings needs the command-line tools its instructions call (git, jq and curl). Our summary lists: The Strix CLI and a completed scan with findings; A Strix cloud login when working from cloud scans.

Does Fix Strix Security Findings access the network?

SKILL.md contains no URLs. Its commands use git and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fix Strix Security Findings safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fix Strix Security Findings use?

Fix Strix Security Findings is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Strix Security Findings use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Strix Security Findings?

Skills that share tags, products or a category with Fix Strix Security Findings: Code Audit (3stoneBrother/code-audit, 893 stars), Security Audit Scanner (ruvnet/ruflo, 74k stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Security and Hardening (addyosmani/agent-skills, 102k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Strix Security Findings?

usestrix (a GitHub organization) maintains it in usestrix/strix, which has 66,916 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: usestrix/strix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.