# Strix Quick Scan vs Deep Scan: Architecture and Behavioral Differences

> Understand Strix quick scan vs deep scan. Discover how quick scan offers rapid feedback and deep scan performs comprehensive penetration testing to find complex flaws.

- Repository: [Strix/strix](https://github.com/usestrix/strix)
- Tags: architecture
- Published: 2026-03-26

---

**Quick scan delivers rapid security feedback in minutes using medium LLM reasoning effort and targeted analysis, while deep scan performs comprehensive 1-4 hour penetration testing with high reasoning effort to uncover complex vulnerability chains and business logic flaws.**

The `usestrix/strix` open-source security scanner implements three distinct scan depths—**quick**, **standard**, and **deep**—that fundamentally alter how the LLM agent approaches code analysis. Understanding the difference between Strix quick scan and deep scan modes is critical for optimizing CI/CD pipelines and security audit workflows.

## Core Differences Between Quick and Deep Scan Modes

### Scan Scope and Duration

**Quick scan** targets time-sensitive environments like pull request checks and pre-commit hooks. It focuses exclusively on recent code changes, authentication flows, and high-severity vulnerability classes including broken access control, remote code execution (RCE), SQL injection, and SSRF. The mode explicitly skips exhaustive enumeration techniques such as subdomain brute-forcing to maintain execution times under several minutes.

**Deep scan** executes a full penetration test methodology lasting between one to four hours. It covers every code path, all input vectors, business logic flows, and vulnerability chaining scenarios. This mode is the default behavior in the Strix CLI, as implemented in [`strix/interface/cli.py`](https://github.com/usestrix/strix/blob/main/strix/interface/cli.py) where the `--scan-mode` argument defaults to `"deep"` when omitted【/cache/repos/github.com/usestrix/strix/main/strix/interface/cli.py#L68-L70】.

### Reconnaissance Depth

Quick scan performs minimal reconnaissance—only a shallow mapping of changed files in white-box contexts and basic endpoint discovery in black-box scenarios. Deep scan conducts exhaustive reconnaissance across the entire attack surface, including source code analysis, dependency CVE enumeration, configuration audits, subdomain discovery, port scanning, API surface mapping, and external integration testing.

### LLM Reasoning Configuration

The scan mode directly controls the LLM's cognitive effort through the `reasoning_effort` parameter. In [`strix/llm/llm.py`](https://github.com/usestrix/strix/blob/main/strix/llm/llm.py), the initialization logic sets `self._reasoning_effort = "medium"` when `scan_mode == "quick"`, whereas deep scans default to high reasoning effort【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L79-L82】. This configuration determines how thoroughly the agent thinks through each attack step and builds vulnerability chains.

## How Scan Modes Work in the Strix Architecture

### CLI Configuration and Defaults

The user-facing interface parses the `--scan-mode` flag and passes the value directly to the LLM configuration layer. The system accepts three validated strings: `"quick"`, `"standard"`, and `"deep"`.

```bash

# Explicit quick scan

strix --target ./my-app --scan-mode quick

# Default deep scan (no flag required)

strix --target ./my-app

```

### LLMConfig Validation

The `LLMConfig` class in [`strix/llm/config.py`](https://github.com/usestrix/strix/blob/main/strix/llm/config.py) validates and normalizes the scan mode input against the allowed values `["quick", "standard", "deep"]`【/cache/repos/github.com/usestrix/strix/main/strix/llm/config.py#L35-L36】. This validation ensures that only supported modes propagate through the system to the agent initialization logic.

### Skill Loading and Prompt Engineering

Each scan mode maps to a dedicated skill file that injects procedural guidance into the LLM system prompt. The `LLM` class method `_get_skills_to_load()` automatically appends `scan_modes/<mode>` to the skill list, loading either [`scan_modes/quick.md`](https://github.com/usestrix/strix/blob/main/scan_modes/quick.md) or [`scan_modes/deep.md`](https://github.com/usestrix/strix/blob/main/scan_modes/deep.md) from the skills directory【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L13-L14】.

The **quick skill** defines a time-boxed workflow targeting recent changes and critical vulnerabilities while explicitly skipping exhaustive enumeration【/cache/repos/github.com/usestrix/strix/main/strix/skills/scan_modes/quick.md】. The **deep skill** outlines a multi-phase methodology including full reconnaissance, business logic deep dives, exhaustive attack surface testing, and vulnerability chaining【/cache/repos/github.com/usestrix/strix/main/strix/skills/scan_modes/deep.md】.

### Telemetry and Observability

Strix records the selected scan mode in telemetry payloads via [`strix/telemetry/posthog.py`](https://github.com/usestrix/strix/blob/main/strix/telemetry/posthog.py), emitting the `scan_mode` field in analytics events to differentiate run types and performance metrics【/cache/repos/github.com/usestrix/strix/main/strix/telemetry/posthog.py#L78-L88】.

## Running Quick and Deep Scans

### Command Line Execution

Execute quick scans for rapid CI/CD feedback:

```bash
strix --target ./my-app --scan-mode quick

```

Run comprehensive deep scans for release audits:

```bash
strix --target ./my-app --scan-mode deep

# Or rely on the default

strix --target ./my-app

```

### Programmatic API Usage

Instantiate the LLM directly with specific configurations for custom automation:

```python
from strix.llm.config import LLMConfig
from strix.llm.llm import LLM

# Quick mode for rapid feedback

quick_cfg = LLMConfig(scan_mode="quick")
quick_llm = LLM(quick_cfg)

# Deep mode for comprehensive analysis

deep_cfg = LLMConfig(scan_mode="deep")
deep_llm = LLM(deep_cfg)

```

The resulting `LLM` objects automatically load the corresponding skill files and apply the appropriate reasoning effort settings based on the configuration.

## Summary

- **Quick scan** provides rapid, cost-effective security feedback suitable for CI/CD pipelines, using medium LLM reasoning and targeting recent changes and high-impact vulnerabilities.
- **Deep scan** delivers exhaustive penetration testing coverage over 1-4 hours, employing high reasoning effort to uncover complex vulnerability chains and business logic flaws.
- **Default behavior** favors security depth: the CLI defaults to deep mode when `--scan-mode` is unspecified, as defined in [`strix/interface/cli.py`](https://github.com/usestrix/strix/blob/main/strix/interface/cli.py).
- **Architectural implementation** spans validation in `LLMConfig`, reasoning effort control in the `LLM` class, and prompt engineering through dedicated skill files in `strix/skills/scan_modes/`.
- **_observability** ensures scan modes are tracked in telemetry via [`strix/telemetry/posthog.py`](https://github.com/usestrix/strix/blob/main/strix/telemetry/posthog.py) for analytics and auditing purposes.

## Frequently Asked Questions

### How do I choose between quick scan and deep scan in Strix?

**Use quick scan for continuous integration workflows and pull request validation where speed matters more than exhaustive coverage.** The quick mode completes in minutes and catches critical vulnerabilities in changed code. Use deep scan for pre-release security audits, compliance checks, and comprehensive assessments where you need full coverage of the attack surface and complex vulnerability chaining analysis.

### What technical differences exist in how Strix processes quick vs deep scans?

**The primary technical differences involve LLM reasoning effort and skill prompt content.** In [`strix/llm/llm.py`](https://github.com/usestrix/strix/blob/main/strix/llm/llm.py), quick scans set `reasoning_effort` to `"medium"` while deep scans use `"high"`【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L79-L82】. Additionally, the system loads distinct skill files—[`scan_modes/quick.md`](https://github.com/usestrix/strix/blob/main/scan_modes/quick.md) versus [`scan_modes/deep.md`](https://github.com/usestrix/strix/blob/main/scan_modes/deep.md)—that provide different procedural instructions to the agent【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L13-L14】.

### Can I use Strix scan modes programmatically without the CLI?

**Yes, the `LLMConfig` and `LLM` classes expose direct programmatic control over scan modes.** Create an `LLMConfig` instance with your desired `scan_mode` parameter and pass it to the `LLM` constructor. The configuration automatically propagates to skill loading and reasoning effort settings without requiring command-line invocation.

### Does Strix support a scan mode between quick and deep?

**Yes, Strix includes a "standard" scan mode that offers intermediate coverage.** The `LLMConfig` validation accepts `"quick"`, `"standard"`, and `"deep"` as valid values【/cache/repos/github.com/usestrix/strix/main/strix/llm/config.py#L35-L36】. Standard mode balances reconnaissance depth with execution time, though the specific reasoning effort and skill configurations for this mode fall between the medium-effort quick scans and high-effort deep scans.