Strix Quick Scan vs Deep Scan: Architecture and Behavioral Differences

Quick scan delivers rapid security feedback in minutes using medium LLM reasoning effort and targeted analysis, while deep scan performs comprehensive 1-4 hour penetration testing with high reasoning effort to uncover complex vulnerability chains and business logic flaws.

The usestrix/strix open-source security scanner implements three distinct scan depths—quick, standard, and deep—that fundamentally alter how the LLM agent approaches code analysis. Understanding the difference between Strix quick scan and deep scan modes is critical for optimizing CI/CD pipelines and security audit workflows.

Core Differences Between Quick and Deep Scan Modes

Scan Scope and Duration

Quick scan targets time-sensitive environments like pull request checks and pre-commit hooks. It focuses exclusively on recent code changes, authentication flows, and high-severity vulnerability classes including broken access control, remote code execution (RCE), SQL injection, and SSRF. The mode explicitly skips exhaustive enumeration techniques such as subdomain brute-forcing to maintain execution times under several minutes.

Deep scan executes a full penetration test methodology lasting between one to four hours. It covers every code path, all input vectors, business logic flows, and vulnerability chaining scenarios. This mode is the default behavior in the Strix CLI, as implemented in strix/interface/cli.py where the --scan-mode argument defaults to "deep" when omitted【/cache/repos/github.com/usestrix/strix/main/strix/interface/cli.py#L68-L70】.

Reconnaissance Depth

Quick scan performs minimal reconnaissance—only a shallow mapping of changed files in white-box contexts and basic endpoint discovery in black-box scenarios. Deep scan conducts exhaustive reconnaissance across the entire attack surface, including source code analysis, dependency CVE enumeration, configuration audits, subdomain discovery, port scanning, API surface mapping, and external integration testing.

LLM Reasoning Configuration

The scan mode directly controls the LLM's cognitive effort through the reasoning_effort parameter. In strix/llm/llm.py, the initialization logic sets self._reasoning_effort = "medium" when scan_mode == "quick", whereas deep scans default to high reasoning effort【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L79-L82】. This configuration determines how thoroughly the agent thinks through each attack step and builds vulnerability chains.

How Scan Modes Work in the Strix Architecture

CLI Configuration and Defaults

The user-facing interface parses the --scan-mode flag and passes the value directly to the LLM configuration layer. The system accepts three validated strings: "quick", "standard", and "deep".


# Explicit quick scan

strix --target ./my-app --scan-mode quick

# Default deep scan (no flag required)

strix --target ./my-app

LLMConfig Validation

The LLMConfig class in strix/llm/config.py validates and normalizes the scan mode input against the allowed values ["quick", "standard", "deep"]【/cache/repos/github.com/usestrix/strix/main/strix/llm/config.py#L35-L36】. This validation ensures that only supported modes propagate through the system to the agent initialization logic.

Skill Loading and Prompt Engineering

Each scan mode maps to a dedicated skill file that injects procedural guidance into the LLM system prompt. The LLM class method _get_skills_to_load() automatically appends scan_modes/<mode> to the skill list, loading either scan_modes/quick.md or scan_modes/deep.md from the skills directory【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L13-L14】.

The quick skill defines a time-boxed workflow targeting recent changes and critical vulnerabilities while explicitly skipping exhaustive enumeration【/cache/repos/github.com/usestrix/strix/main/strix/skills/scan_modes/quick.md】. The deep skill outlines a multi-phase methodology including full reconnaissance, business logic deep dives, exhaustive attack surface testing, and vulnerability chaining【/cache/repos/github.com/usestrix/strix/main/strix/skills/scan_modes/deep.md】.

Telemetry and Observability

Strix records the selected scan mode in telemetry payloads via strix/telemetry/posthog.py, emitting the scan_mode field in analytics events to differentiate run types and performance metrics【/cache/repos/github.com/usestrix/strix/main/strix/telemetry/posthog.py#L78-L88】.

Running Quick and Deep Scans

Command Line Execution

Execute quick scans for rapid CI/CD feedback:

strix --target ./my-app --scan-mode quick

Run comprehensive deep scans for release audits:

strix --target ./my-app --scan-mode deep

# Or rely on the default

strix --target ./my-app

Programmatic API Usage

Instantiate the LLM directly with specific configurations for custom automation:

from strix.llm.config import LLMConfig
from strix.llm.llm import LLM

# Quick mode for rapid feedback

quick_cfg = LLMConfig(scan_mode="quick")
quick_llm = LLM(quick_cfg)

# Deep mode for comprehensive analysis

deep_cfg = LLMConfig(scan_mode="deep")
deep_llm = LLM(deep_cfg)

The resulting LLM objects automatically load the corresponding skill files and apply the appropriate reasoning effort settings based on the configuration.

Summary

  • Quick scan provides rapid, cost-effective security feedback suitable for CI/CD pipelines, using medium LLM reasoning and targeting recent changes and high-impact vulnerabilities.
  • Deep scan delivers exhaustive penetration testing coverage over 1-4 hours, employing high reasoning effort to uncover complex vulnerability chains and business logic flaws.
  • Default behavior favors security depth: the CLI defaults to deep mode when --scan-mode is unspecified, as defined in strix/interface/cli.py.
  • Architectural implementation spans validation in LLMConfig, reasoning effort control in the LLM class, and prompt engineering through dedicated skill files in strix/skills/scan_modes/.
  • _observability ensures scan modes are tracked in telemetry via strix/telemetry/posthog.py for analytics and auditing purposes.

Frequently Asked Questions

How do I choose between quick scan and deep scan in Strix?

Use quick scan for continuous integration workflows and pull request validation where speed matters more than exhaustive coverage. The quick mode completes in minutes and catches critical vulnerabilities in changed code. Use deep scan for pre-release security audits, compliance checks, and comprehensive assessments where you need full coverage of the attack surface and complex vulnerability chaining analysis.

What technical differences exist in how Strix processes quick vs deep scans?

The primary technical differences involve LLM reasoning effort and skill prompt content. In strix/llm/llm.py, quick scans set reasoning_effort to "medium" while deep scans use "high"【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L79-L82】. Additionally, the system loads distinct skill files—scan_modes/quick.md versus scan_modes/deep.md—that provide different procedural instructions to the agent【/cache/repos/github.com/usestrix/strix/main/strix/llm/llm.py#L13-L14】.

Can I use Strix scan modes programmatically without the CLI?

Yes, the LLMConfig and LLM classes expose direct programmatic control over scan modes. Create an LLMConfig instance with your desired scan_mode parameter and pass it to the LLM constructor. The configuration automatically propagates to skill loading and reasoning effort settings without requiring command-line invocation.

Does Strix support a scan mode between quick and deep?

Yes, Strix includes a "standard" scan mode that offers intermediate coverage. The LLMConfig validation accepts "quick", "standard", and "deep" as valid values【/cache/repos/github.com/usestrix/strix/main/strix/llm/config.py#L35-L36】. Standard mode balances reconnaissance depth with execution time, though the specific reasoning effort and skill configurations for this mode fall between the medium-effort quick scans and high-effort deep scans.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →