Loading...
Loading...
Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.
npx skill4agent add usestrix/strix web-app-penetration-testingstrix --versionstrix -n -t https://staging.example.com --max-budget 20 \
--instruction "Test account: qa@example.com / <password>. In scope: /app/*, /api/*. Do not touch /billing or send email. Focus on access control between the two seeded orgs."--instruction--instruction-file-t https://github.com/org/app -t https://staging.example.comhttp://host.docker.internal:3000--scan-mode quickstandarddeep--max-budgetstrix_runs/<run>/penetration_test_report.mdvulnerabilities/0210run.json--max-budget