Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

strixstrix 搜索

Agent Skill

strix 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,597

周安装

64

GitHub Stars

11

下载量

517
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:strix(strix 搜索)
来源仓库:https://github.com/akillness/oh-my-skills
仓库路径:skills/strix
安装命令:
npx skills add https://github.com/akillness/oh-my-skills --skill strix
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/akillness/oh-my-skills --skill strix

简介

strix 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中快速定位候选结果。

  • 它支持基于关键词、任务场景或来源线索进行信息匹配与过滤,适用于研究类任务。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装,具体用法需结合 README 进一步确认。
  • 安装前建议核实权限范围、维护状态,并注意是否涉及联网、命令执行或文件读写操作。
  • strix 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

strix - AI-Driven Application Security Testing

Keyword: strix · ai pentest · vulnerability scan cli · strix ci Only use Strix against systems you own or are explicitly authorized to test.

Strix is an AI-driven application security CLI. It runs scans inside a Docker-backed sandbox, uses an LLM provider for reasoning, and can assess local directories, GitHub repositories, live URLs, domains, and multi-target combinations.

When to use this skill

  • Install Strix and verify Docker plus sandbox readiness
  • Configure STRIX_LLM, LLM_API_KEY, optional LLM_API_BASE, and related runtime settings
  • Run local white-box scans against a repository or directory
  • Run black-box or grey-box scans against staging or production-like URLs you are authorized to test
  • Pass credentials, scope, or rules of engagement with --instruction or --instruction-file
  • Choose the right scan depth: quick, standard, or deep
  • Run Strix headlessly in CI/CD and interpret exit codes
  • Understand Strix's internal security "skills" and how they differ from this repo's skills

Instructions

Step 1: Install and preflight

  1. Run bash scripts/install.sh
  2. Confirm strix --version succeeds
  3. Ensure Docker is installed and the daemon is running
  4. Let the installer pull the sandbox image on first setup unless you intentionally skip it
  5. For manual installation alternatives and direct commands, see references/commands.md

Step 2: Configure the model provider

Set the minimum required environment variables before running a scan:

export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"

Optional runtime variables:

  • LLM_API_BASE for OpenAI-compatible proxies or local endpoints
  • PERPLEXITY_API_KEY for web search during scans
  • STRIX_REASONING_EFFORT to tune model effort
  • STRIX_DISABLE_BROWSER=true when UI automation is unnecessary
  • STRIX_TELEMETRY=0 to disable telemetry defaults

Provider examples, config-file format, and optional environment variables are in references/providers-and-config.md.

Step 3: Pick the target and scan mode

Strix accepts these target types:

  • Local directory: ./app
  • GitHub repository URL: https://github.com/org/repo
  • Live web app URL: https://staging.example.com
  • Domain or IP
  • Multi-target scans via repeated --target or -t

Scan modes:

  • quick: PR checks, smoke tests, fast CI feedback
  • standard: routine security reviews
  • deep: default full assessment and longer bug-bounty-style exploration

Detailed mode and CI guidance lives in references/scan-modes-and-ci.md.

Step 4: Run the scan

Use bash scripts/run-scan.sh for a repeatable wrapper or call strix directly.

Common direct commands:

strix --target ./app
strix --target https://github.com/org/repo
strix --target https://staging.example.com --instruction-file ./instruction.md
strix -t https://github.com/org/repo -t https://staging.example.com

When authenticated or scoped testing matters, prefer --instruction-file over long inline prompts so credentials, exclusions, and rules of engagement stay explicit and reviewable.

Step 5: Review outputs and iterate

Strix stores results under strix_runs/<run-name>.

Exit codes to remember:

  • 0: completed without findings
  • 1: execution or environment error
  • 2: vulnerabilities found in headless mode

Use the run artifacts to confirm what Strix tested, what it found, and what needs revalidation after fixes.

Step 6: Automate in CI/CD

Use headless mode in automation:

strix -n --target ./ --scan-mode quick

CI runners need Docker access. For pull requests, default to quick; reserve standard or deep for scheduled or release-stage jobs. See references/scan-modes-and-ci.md and scripts/ci-scan.sh.

Step 7: Understand Strix internal skills

Strix has its own internal security knowledge packs under strix/skills/. They are not the same as this repo's agent skills.

  • Strix auto-selects up to 5 relevant internal skills per task
  • Categories include vulnerabilities, frameworks, technologies, protocols, and tooling
  • These internal skills enrich Strix agent behavior during the scan itself

See references/built-in-skills.md before assuming "skill" means the same thing across both ecosystems.

Examples

Example 1: Quick PR scan of a local repository

export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"
strix -n --target ./ --scan-mode quick

Example 2: Standard scan of a GitHub repository

strix --target https://github.com/acme/payments --scan-mode standard

Example 3: Grey-box scan of a staging URL

strix --target https://staging.example.com \
  --instruction-file ./instruction.md \
  --scan-mode deep

Example 4: Combined repo plus live target

strix -t https://github.com/acme/payments \
  -t https://staging.example.com \
  --instruction "Correlate source paths with exposed runtime issues"

Example 5: Browser-disabled API-focused scan

STRIX_DISABLE_BROWSER=true \
strix --target https://api.example.com --scan-mode standard

Example 6: Scripted run wrapper

bash scripts/run-scan.sh \
  --target ./app \
  --scan-mode quick \
  --non-interactive

Best practices

  1. Only test assets you own or are explicitly permitted to assess.
  2. Start with quick in CI and widen depth only when signal justifies the extra runtime.
  3. Keep secrets in environment variables, secret stores, or instruction files under your control instead of scattering them inline.
  4. Use both source and live targets together when you need better reproduction and remediation context.
  5. Expect the first run to be slower because Strix may pull its sandbox image.
  6. Treat strix_runs/ as evidence: archive useful runs, especially when findings are heading into triage or remediation.
  7. Be explicit about scope, exclusions, credentials, and rate limits so Strix does not waste time exploring irrelevant surfaces.
  8. Distinguish this repo's strix skill from Strix internal skills to avoid instruction confusion.

References

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.54%
按下载量换算184

Claude

28.56%
按下载量换算148

Cursor

17.09%
按下载量换算88

Gemini CLI

9.73%
按下载量换算50

安全审计

Gen Agent Trust Hub

未通过

Socket

可疑

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills