A proper penetration test costs thousands. Strix is open source and does the one thing a scanner never does: it runs your app, breaks in, and writes a working exploit to prove every bug it finds.

The reel said “free.” That word needs an asterisk. This issue is the asterisk: the exact setup that runs a real Strix pentest for $0, the CI job that does it on every pull request, and how to read the report it hands back.

What Strix actually is

Strix (strix) is an open-source AI penetration tester. It doesn’t read your code like a linter. It spins your app up in a Docker sandbox, attacks it the way a hacker would, and for every hole it confirms it writes a working exploit to prove it — with a CVSS severity and an OWASP class attached.

Apache-2.0. 47,826 stars in its first year, created 5 Aug 2025. Repo: github.com/usestrix/strix

What it’s for: point it at your own app. That is the only thing it is for. A scanner hands you a hundred maybes; this hands you the three that are real. That is the whole reason to run it.

What “free” actually means

The tool is free — Apache-2.0, nothing to pay. But it needs two things to run: Docker running, and a model to think with. The model is the only place a bill can appear.

Point Strix at a metered API (OpenAI and the like) and you pay per token. Point it at a model you already have, or a free tier, and the scan itself costs $0.00. Three $0 routes below — pick the one that fits your machine.

1. Install and first scan

Prerequisite: Docker running. Then:

# install
curl -sSL https://strix.ai/install | bash

# tell it which model to use
export STRIX_LLM="openai/gpt-5.4"
export LLM_API_KEY="your-api-key"

# point it at your app
strix --target ./app-directory

First run pulls the sandbox Docker image and saves everything to a strix_runs/RUN-NAME folder. That STRIX_LLM line is exactly where the $0 happens. Keep reading.

2. Run it for $0 — three routes

Route 1 — a model on your own machine (Ollama, LMStudio):

export STRIX_LLM="ollama/qwen2.5-coder"       # e.g.
export LLM_API_BASE="http://localhost:11434"  # your local server
export LLM_API_KEY="local"                    # any non-empty string; local ignores it
strix --target ./app-directory

The LLM_API_BASE line is the whole trick — it’s the one the quick-start leaves out. Strix routes models through LiteLLM, so the provider/model string follows LiteLLM’s naming (ollama/MODEL). Nothing leaves your machine, no meter. Honest caveat: a local model good enough to find real bugs wants real hardware. No GPU? Use route 2 or 3.

Route 2 — a free tier (what I actually ran)

Point STRIX_LLM at any model carrying a :free tag and drop in a free-tier key:

export STRIX_LLM="openrouter/MODEL:free"
export LLM_API_KEY="sk-or-your-openrouter-key"
strix --target ./app-directory

I ran exactly this against a real app. Cost on the bill: $0.00. It found three real vulnerabilities, one a critical SQL injection scoring 9.4 — each with an exploit I could reproduce.

Route 3 — a ChatGPT subscription you already pay for. No new API key, no per-token meter; it rides the sub you’ve got:

strix auth login chatgpt
export STRIX_LLM="chatgpt/gpt-5.4"
strix --target ./app-directory

3. The CI setup — pentest every pull request

Drop this in .github/workflows and every PR gets pentested. In CI it auto-scopes to the changed files, so it stays fast:

name: strix-penetration-test
on:
  pull_request:
jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
        with:
          fetch-depth: 0
      - name: Install Strix
        run: curl -sSL https://strix.ai/install | bash
      - name: Run Strix
        env:
          STRIX_LLM: ${{ secrets.STRIX_LLM }}
          LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
        run: strix -n -t ./ --scan-mode quick

Put STRIX_LLM and LLM_API_KEY in your repo secrets. Use a $0 model there too and your pipeline security costs nothing but CI minutes.

4. Read the report — the three that are real

Every scan writes to disk as it runs. Bring it up locally:

strix view          # the most recent run
strix view my-run   # a specific run by name

That starts a local server on 127.0.0.1, random port, tokened link. Nothing uploads. What you’re reading:

In the dashboard

What it shows

Overview

target + a severity breakdown: Critical / High / Medium / Low / Info

Vulnerabilities

each validated finding, its severity, details and reproduction steps

Per finding

a CVSS score and an OWASP class

The point: these are validated. A scanner lists a hundred possibles; Strix only surfaces the ones it actually broke in through and wrote an exploit for. My run: three. That is the proof-not-warning gap in one screen.

Run it against something tonight, the $0 way, and reply with what it turned up. I read every one.

Talk soon,
Mike

PS — this is the kind of build I wire into businesses at optimax-ai.com.