# What Vulnerability Categories Does Strix Detect? Complete OWASP Coverage Guide

> Strix detects 16+ vulnerability categories like SQL injection and XSS, fully covering the OWASP Top 10 with modular Markdown skill files. Discover comprehensive security.

- Repository: [Strix/strix](https://github.com/usestrix/strix)
- Tags: deep-dive
- Published: 2026-03-26

---

**Strix detects 16+ vulnerability categories—including SQL injection, XSS, JWT attacks, and business logic flaws—through modular Markdown skill files that map directly to the OWASP Top 10 framework.**

The open-source Strix project (usestrix/strix) approaches security testing through a unique skill-based architecture. Instead of relying on generic LLM knowledge, Strix injects specialist vulnerability detection capabilities into its agents using lightweight Markdown skill files. This design ensures comprehensive coverage of modern web application vulnerabilities while maintaining strict alignment with industry standards like the OWASP Top 10.

## How Strix Structures Vulnerability Detection

Strix detects vulnerabilities through **skill files**—lightweight Markdown documents that describe a specific attack class, its attack surface, methodology, payloads, bypasses, and validation steps. These files reside in the `strix/skills/vulnerabilities/` directory of the repository.

When an agent is launched, the runtime selects the most relevant skills (up to five) based on the target and user-provided instructions. According to the source code in [`strix/runtime/runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/runtime.py), each selected skill is injected into the LLM's system prompt, giving the agent deep, specialist knowledge that goes far beyond the generic "SQL-i, XSS" awareness of a plain language model.

## Complete List of Vulnerability Categories

The **vulnerability categories** are defined in individual Markdown files within the `strix/skills/vulnerabilities/` subdirectory. The human-readable reference is maintained in `docs/advanced/skills.mdx`, which groups these into a comprehensive matrix:

| Category | Description | Skill File |
| --- | --- | --- |
| **Authentication / JWT** | JWT attacks, algorithm confusion, claim tampering | [`authentication_jwt.md`](https://github.com/usestrix/strix/blob/main/authentication_jwt.md) |
| **IDOR** | Object-reference attacks, horizontal/vertical access control bypasses | [`idor.md`](https://github.com/usestrix/strix/blob/main/idor.md) |
| **SQL Injection** | Classic, blind, error-based, and WAF-bypass techniques | [`sql_injection.md`](https://github.com/usestrix/strix/blob/main/sql_injection.md) |
| **XSS** | Reflected, stored, DOM-based, and CSP-bypass methods | [`xss.md`](https://github.com/usestrix/strix/blob/main/xss.md) |
| **SSRF** | Server-side request forgery, protocol handlers, and internal probing | [`ssrf.md`](https://github.com/usestrix/strix/blob/main/ssrf.md) |
| **CSRF** | Token-bypass techniques and double-submit pattern exploitation | [`csrf.md`](https://github.com/usestrix/strix/blob/main/csrf.md) |
| **XXE** | XML external entities, OOB exfiltration, and parser abuse | [`xxe.md`](https://github.com/usestrix/strix/blob/main/xxe.md) |
| **RCE** | Remote code execution via deserialization, command injection, and eval attacks | [`rce.md`](https://github.com/usestrix/strix/blob/main/rce.md) |
| **Business Logic** | Logic flaws, state manipulation, and workflow abuse | [`business_logic.md`](https://github.com/usestrix/strix/blob/main/business_logic.md) |
| **Race Conditions** | TOCTOU vulnerabilities and parallel request attacks | [`race_conditions.md`](https://github.com/usestrix/strix/blob/main/race_conditions.md) |
| **Path Traversal / LFI / RFI** | File inclusion, directory traversal, and arbitrary file reads | [`path_traversal_lfi_rfi.md`](https://github.com/usestrix/strix/blob/main/path_traversal_lfi_rfi.md) |
| **Open Redirect** | URL parsing tricks, redirect bypasses, and header injection | [`open_redirect.md`](https://github.com/usestrix/strix/blob/main/open_redirect.md) |
| **Mass Assignment** | Hidden parameter injection and object property tampering | [`mass_assignment.md`](https://github.com/usestrix/strix/blob/main/mass_assignment.md) |
| **Insecure File Uploads** | MIME-type bypass, extension tricks, and archive attacks | [`insecure_file_uploads.md`](https://github.com/usestrix/strix/blob/main/insecure_file_uploads.md) |
| **Information Disclosure** | Error-based enumeration, verbose messaging, and data leakage | [`information_disclosure.md`](https://github.com/usestrix/strix/blob/main/information_disclosure.md) |
| **Subdomain Takeover** | Dangling DNS records and unclaimed cloud resource exploitation | [`subdomain_takeover.md`](https://github.com/usestrix/strix/blob/main/subdomain_takeover.md) |
| **Broken Function-Level Authorization** | Privilege escalation via API misuse and endpoint access | [`broken_function_level_authorization.md`](https://github.com/usestrix/strix/blob/main/broken_function_level_authorization.md) |

## OWASP Top 10 Coverage Mapping

Strix aligns its detection capabilities directly with the **OWASP Top 10** framework. The following mapping illustrates how specific skills address each risk category:

| OWASP Top 10 Category | Strix Skill Coverage |
| --- | --- |
| **A1 – Broken Authentication** | `authentication_jwt`, `csrf` |
| **A2 – Cryptographic Failures** | Indirectly covered via JWT skill (algorithm confusion, weak signing) |
| **A3 – Injection** | `sql_injection`, `xss`, `command_injection` (via RCE skill) |
| **A4 – Insecure Design** | `business_logic`, `race_conditions` |
| **A5 – Security Misconfiguration** | `information_disclosure`, `subdomain_takeover` |
| **A6 – Vulnerable Components** | `nuclei` templates (via sandbox tools integration) |
| **A7 – Identification and Authentication Failures** | `authentication_jwt`, `csrf` |
| **A8 – Software and Data Integrity Failures** | `rce` (deserialization attacks), `xxe` |
| **A9 – Security Logging and Monitoring** | Telemetry flags in [`strix/telemetry/tracer.py`](https://github.com/usestrix/strix/blob/main/strix/telemetry/tracer.py) (indirect coverage) |
| **A10 – Server-Side Request Forgery** | `ssrf` |

Additionally, Strix ships with a **pre-installed OWASP Zed Attack Proxy (ZAP)** as part of its sandbox toolset, documented in `docs/tools/sandbox.mdx`. Agents can invoke ZAP automatically when a skill requires active web-application probing, providing out-of-the-box coverage for the OWASP testing methodology.

## Running Scans with Specific Vulnerability Categories

You can target specific vulnerability categories using CLI flags or programmatic APIs. The runtime dynamically loads only the relevant skill files into the agent's context.

Run a full standard scan with automatic skill selection:

```bash
strix --target https://demo.app --scan-mode standard

```

Focus the scan on specific OWASP injection categories:

```bash
strix --target https://demo.app \
      --instruction "Focus on injection flaws – SQLi and XSS"

```

Load a custom skill file for proprietary vulnerability detection:

```bash
strix --target https://demo.app \
      --instruction-file ./my_custom_skill.md

```

Programmatically create an agent with specific skills:

```python
from strix.runtime import create_agent

agent = create_agent(
    task="Test web app for client-side attacks",
    skills=["xss", "ssrf"]
)
agent.run()

```

## Core Implementation Files

The following source files define Strix's vulnerability detection engine:

- **`docs/advanced/skills.mdx`** – Human-readable overview of all skill categories and the vulnerability matrix.
- **`strix/skills/vulnerabilities/*.md`** – Individual Markdown skill definitions (e.g., [`sql_injection.md`](https://github.com/usestrix/strix/blob/main/sql_injection.md), [`xss.md`](https://github.com/usestrix/strix/blob/main/xss.md)).
- **[`strix/runtime/runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/runtime.py)** – Core agent orchestration logic that loads selected skills into the LLM prompt.
- **`docs/tools/sandbox.mdx`** – Documentation for bundled security tools, including the OWASP ZAP integration.
- **[`strix/telemetry/tracer.py`](https://github.com/usestrix/strix/blob/main/strix/telemetry/tracer.py)** – Tracks generated vulnerability reports and aggregates counts for UI/reporting.
- **[`tests/tools/test_load_skill_tool.py`](https://github.com/usestrix/strix/blob/main/tests/tools/test_load_skill_tool.py)** – Test suite verifying skill loading functionality.

## Summary

- Strix detects **17 distinct vulnerability categories** through modular Markdown skill files stored in `strix/skills/vulnerabilities/`.
- The runtime selects up to **five relevant skills** per scan, injecting them into the LLM system prompt for specialist-level detection.
- **OWASP Top 10 coverage** is comprehensive, with explicit skills mapping to A1 (Broken Authentication), A3 (Injection), A4 (Insecure Design), A5 (Security Misconfiguration), A7 (Authentication Failures), A8 (Integrity Failures), and A10 (SSRF).
- **OWASP ZAP** comes pre-installed in the Strix sandbox, enabling active scanning capabilities alongside LLM-driven analysis.
- Custom vulnerability categories can be added via user-defined skill files without modifying core source code.

## Frequently Asked Questions

### How does Strix detect vulnerabilities differently than traditional scanners?

Traditional scanners rely on static signatures or predefined payloads. Strix uses **skill files**—Markdown documents containing attack methodologies, bypass techniques, and validation steps—that are dynamically loaded into an LLM agent's context. This allows Strix to adapt its detection logic based on the target's specific technology stack and behavior, combining the depth of manual penetration testing with automation scale.

### Which OWASP Top 10 categories does Strix fully cover?

Strix provides direct skill coverage for **A1 (Broken Authentication)**, **A3 (Injection)**, **A4 (Insecure Design)**, **A5 (Security Misconfiguration)**, **A7 (Identification and Authentication Failures)**, **A8 (Software and Data Integrity Failures)**, and **A10 (Server-Side Request Forgery)**. Categories A2 (Cryptographic Failures) and A6 (Vulnerable Components) are addressed indirectly through JWT analysis and Nuclei template integration, while A9 (Logging/Monitoring) relies on telemetry implementation rather than active detection skills.

### Can I add custom vulnerability categories to Strix?

Yes. You can create new vulnerability categories by authoring custom skill files in Markdown format and passing them via the `--instruction-file` parameter. These files follow the same structure as native skills in `strix/skills/vulnerabilities/`, allowing you to define attack surfaces, payloads, and validation steps for proprietary or niche vulnerabilities without modifying the core codebase.

### How many vulnerability skills can Strix load simultaneously?

The Strix runtime loads up to **five skills** per agent invocation. This limit ensures the LLM context window remains focused and performant while still allowing multi-vector testing (e.g., combining `sql_injection`, `xss`, `business_logic`, `idor`, and `authentication_jwt` for a comprehensive web application assessment).