A proper penetration test costs thousands. Strix is open source and does the one thing a scanner never does: it runs your app, breaks in, and writes a working exploit to prove every bug it finds.
The reel said “free.” That word needs an asterisk. This issue is the asterisk: the exact setup that runs a real Strix pentest for $0, the CI job that does it on every pull request, and how to read the report it hands back.
What Strix actually is
Strix (strix) is an open-source AI penetration tester. It doesn’t read your code like a linter. It spins your app up in a Docker sandbox, attacks it the way a hacker would, and for every hole it confirms it writes a working exploit to prove it — with a CVSS severity and an OWASP class attached.
Apache-2.0. 47,826 stars in its first year, created 5 Aug 2025. Repo: github.com/usestrix/strix
What it’s for: point it at your own app. That is the only thing it is for. A scanner hands you a hundred maybes; this hands you the three that are real. That is the whole reason to run it.
What “free” actually means
The tool is free — Apache-2.0, nothing to pay. But it needs two things to run: Docker running, and a model to think with. The model is the only place a bill can appear.
Point Strix at a metered API (OpenAI and the like) and you pay per token. Point it at a model you already have, or a free tier, and the scan itself costs $0.00. Three $0 routes below — pick the one that fits your machine.
1. Install and first scan
Prerequisite: Docker running. Then:
# install
curl -sSL https://strix.ai/install | bash
# tell it which model to use
export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"
# point it at your app
strix --target ./app-directoryFirst run pulls the sandbox Docker image and saves everything to a strix_runs/RUN-NAME folder. That STRIX_LLM line is exactly where the $0 happens. Keep reading.
2. Run it for $0 — three routes
Route 1 — a model on your own machine (Ollama, LMStudio):
export STRIX_LLM="ollama/qwen2.5-coder" # e.g.
export LLM_API_BASE="http://localhost:11434" # your local server
export LLM_API_KEY="local" # any non-empty string; local ignores it
strix --target ./app-directoryThe LLM_API_BASE line is the whole trick — it’s the one the quick-start leaves out. Strix routes models through LiteLLM, so the provider/model string follows LiteLLM’s naming (ollama/MODEL). Nothing leaves your machine, no meter. Honest caveat: a local model good enough to find real bugs wants real hardware. No GPU? Use route 2 or 3.
Route 2 — a free tier (what I actually ran)
Point STRIX_LLM at any model carrying a :free tag and drop in a free-tier key:
export STRIX_LLM="openrouter/MODEL:free"
export LLM_API_KEY="sk-or-your-openrouter-key"
strix --target ./app-directoryI ran exactly this against a real app. Cost on the bill: $0.00. It found three real vulnerabilities, one a critical SQL injection scoring 9.4 — each with an exploit I could reproduce.
Route 3 — a ChatGPT subscription you already pay for. No new API key, no per-token meter; it rides the sub you’ve got:
strix auth login chatgpt
export STRIX_LLM="chatgpt/gpt-5.4"
strix --target ./app-directory3. The CI setup — pentest every pull request
Drop this in .github/workflows and every PR gets pentested. In CI it auto-scopes to the changed files, so it stays fast:
name: strix-penetration-test
on:
pull_request:
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Install Strix
run: curl -sSL https://strix.ai/install | bash
- name: Run Strix
env:
STRIX_LLM: ${{ secrets.STRIX_LLM }}
LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
run: strix -n -t ./ --scan-mode quickPut STRIX_LLM and LLM_API_KEY in your repo secrets. Use a $0 model there too and your pipeline security costs nothing but CI minutes.
4. Read the report — the three that are real
Every scan writes to disk as it runs. Bring it up locally:
strix view # the most recent run
strix view my-run # a specific run by nameThat starts a local server on 127.0.0.1, random port, tokened link. Nothing uploads. What you’re reading:
In the dashboard | What it shows |
|---|---|
Overview | target + a severity breakdown: Critical / High / Medium / Low / Info |
Vulnerabilities | each validated finding, its severity, details and reproduction steps |
Per finding | a CVSS score and an OWASP class |
The point: these are validated. A scanner lists a hundred possibles; Strix only surfaces the ones it actually broke in through and wrote an exploit for. My run: three. That is the proof-not-warning gap in one screen.
Run it against something tonight, the $0 way, and reply with what it turned up. I read every one.
Talk soon,
Mike
PS — this is the kind of build I wire into businesses at optimax-ai.com.