What Vulnerability Categories Does Strix Detect? Complete OWASP Coverage Guide
Strix detects 16+ vulnerability categories—including SQL injection, XSS, JWT attacks, and business logic flaws—through modular Markdown skill files that map directly to the OWASP Top 10 framework.
The open-source Strix project (usestrix/strix) approaches security testing through a unique skill-based architecture. Instead of relying on generic LLM knowledge, Strix injects specialist vulnerability detection capabilities into its agents using lightweight Markdown skill files. This design ensures comprehensive coverage of modern web application vulnerabilities while maintaining strict alignment with industry standards like the OWASP Top 10.
How Strix Structures Vulnerability Detection
Strix detects vulnerabilities through skill files—lightweight Markdown documents that describe a specific attack class, its attack surface, methodology, payloads, bypasses, and validation steps. These files reside in the strix/skills/vulnerabilities/ directory of the repository.
When an agent is launched, the runtime selects the most relevant skills (up to five) based on the target and user-provided instructions. According to the source code in strix/runtime/runtime.py, each selected skill is injected into the LLM's system prompt, giving the agent deep, specialist knowledge that goes far beyond the generic "SQL-i, XSS" awareness of a plain language model.
Complete List of Vulnerability Categories
The vulnerability categories are defined in individual Markdown files within the strix/skills/vulnerabilities/ subdirectory. The human-readable reference is maintained in docs/advanced/skills.mdx, which groups these into a comprehensive matrix:
| Category | Description | Skill File |
|---|---|---|
| Authentication / JWT | JWT attacks, algorithm confusion, claim tampering | authentication_jwt.md |
| IDOR | Object-reference attacks, horizontal/vertical access control bypasses | idor.md |
| SQL Injection | Classic, blind, error-based, and WAF-bypass techniques | sql_injection.md |
| XSS | Reflected, stored, DOM-based, and CSP-bypass methods | xss.md |
| SSRF | Server-side request forgery, protocol handlers, and internal probing | ssrf.md |
| CSRF | Token-bypass techniques and double-submit pattern exploitation | csrf.md |
| XXE | XML external entities, OOB exfiltration, and parser abuse | xxe.md |
| RCE | Remote code execution via deserialization, command injection, and eval attacks | rce.md |
| Business Logic | Logic flaws, state manipulation, and workflow abuse | business_logic.md |
| Race Conditions | TOCTOU vulnerabilities and parallel request attacks | race_conditions.md |
| Path Traversal / LFI / RFI | File inclusion, directory traversal, and arbitrary file reads | path_traversal_lfi_rfi.md |
| Open Redirect | URL parsing tricks, redirect bypasses, and header injection | open_redirect.md |
| Mass Assignment | Hidden parameter injection and object property tampering | mass_assignment.md |
| Insecure File Uploads | MIME-type bypass, extension tricks, and archive attacks | insecure_file_uploads.md |
| Information Disclosure | Error-based enumeration, verbose messaging, and data leakage | information_disclosure.md |
| Subdomain Takeover | Dangling DNS records and unclaimed cloud resource exploitation | subdomain_takeover.md |
| Broken Function-Level Authorization | Privilege escalation via API misuse and endpoint access | broken_function_level_authorization.md |
OWASP Top 10 Coverage Mapping
Strix aligns its detection capabilities directly with the OWASP Top 10 framework. The following mapping illustrates how specific skills address each risk category:
| OWASP Top 10 Category | Strix Skill Coverage |
|---|---|
| A1 – Broken Authentication | authentication_jwt, csrf |
| A2 – Cryptographic Failures | Indirectly covered via JWT skill (algorithm confusion, weak signing) |
| A3 – Injection | sql_injection, xss, command_injection (via RCE skill) |
| A4 – Insecure Design | business_logic, race_conditions |
| A5 – Security Misconfiguration | information_disclosure, subdomain_takeover |
| A6 – Vulnerable Components | nuclei templates (via sandbox tools integration) |
| A7 – Identification and Authentication Failures | authentication_jwt, csrf |
| A8 – Software and Data Integrity Failures | rce (deserialization attacks), xxe |
| A9 – Security Logging and Monitoring | Telemetry flags in strix/telemetry/tracer.py (indirect coverage) |
| A10 – Server-Side Request Forgery | ssrf |
Additionally, Strix ships with a pre-installed OWASP Zed Attack Proxy (ZAP) as part of its sandbox toolset, documented in docs/tools/sandbox.mdx. Agents can invoke ZAP automatically when a skill requires active web-application probing, providing out-of-the-box coverage for the OWASP testing methodology.
Running Scans with Specific Vulnerability Categories
You can target specific vulnerability categories using CLI flags or programmatic APIs. The runtime dynamically loads only the relevant skill files into the agent's context.
Run a full standard scan with automatic skill selection:
strix --target https://demo.app --scan-mode standard
Focus the scan on specific OWASP injection categories:
strix --target https://demo.app \
--instruction "Focus on injection flaws – SQLi and XSS"
Load a custom skill file for proprietary vulnerability detection:
strix --target https://demo.app \
--instruction-file ./my_custom_skill.md
Programmatically create an agent with specific skills:
from strix.runtime import create_agent
agent = create_agent(
task="Test web app for client-side attacks",
skills=["xss", "ssrf"]
)
agent.run()
Core Implementation Files
The following source files define Strix's vulnerability detection engine:
docs/advanced/skills.mdx– Human-readable overview of all skill categories and the vulnerability matrix.strix/skills/vulnerabilities/*.md– Individual Markdown skill definitions (e.g.,sql_injection.md,xss.md).strix/runtime/runtime.py– Core agent orchestration logic that loads selected skills into the LLM prompt.docs/tools/sandbox.mdx– Documentation for bundled security tools, including the OWASP ZAP integration.strix/telemetry/tracer.py– Tracks generated vulnerability reports and aggregates counts for UI/reporting.tests/tools/test_load_skill_tool.py– Test suite verifying skill loading functionality.
Summary
- Strix detects 17 distinct vulnerability categories through modular Markdown skill files stored in
strix/skills/vulnerabilities/. - The runtime selects up to five relevant skills per scan, injecting them into the LLM system prompt for specialist-level detection.
- OWASP Top 10 coverage is comprehensive, with explicit skills mapping to A1 (Broken Authentication), A3 (Injection), A4 (Insecure Design), A5 (Security Misconfiguration), A7 (Authentication Failures), A8 (Integrity Failures), and A10 (SSRF).
- OWASP ZAP comes pre-installed in the Strix sandbox, enabling active scanning capabilities alongside LLM-driven analysis.
- Custom vulnerability categories can be added via user-defined skill files without modifying core source code.
Frequently Asked Questions
How does Strix detect vulnerabilities differently than traditional scanners?
Traditional scanners rely on static signatures or predefined payloads. Strix uses skill files—Markdown documents containing attack methodologies, bypass techniques, and validation steps—that are dynamically loaded into an LLM agent's context. This allows Strix to adapt its detection logic based on the target's specific technology stack and behavior, combining the depth of manual penetration testing with automation scale.
Which OWASP Top 10 categories does Strix fully cover?
Strix provides direct skill coverage for A1 (Broken Authentication), A3 (Injection), A4 (Insecure Design), A5 (Security Misconfiguration), A7 (Identification and Authentication Failures), A8 (Software and Data Integrity Failures), and A10 (Server-Side Request Forgery). Categories A2 (Cryptographic Failures) and A6 (Vulnerable Components) are addressed indirectly through JWT analysis and Nuclei template integration, while A9 (Logging/Monitoring) relies on telemetry implementation rather than active detection skills.
Can I add custom vulnerability categories to Strix?
Yes. You can create new vulnerability categories by authoring custom skill files in Markdown format and passing them via the --instruction-file parameter. These files follow the same structure as native skills in strix/skills/vulnerabilities/, allowing you to define attack surfaces, payloads, and validation steps for proprietary or niche vulnerabilities without modifying the core codebase.
How many vulnerability skills can Strix load simultaneously?
The Strix runtime loads up to five skills per agent invocation. This limit ensures the LLM context window remains focused and performant while still allowing multi-vector testing (e.g., combining sql_injection, xss, business_logic, idor, and authentication_jwt for a comprehensive web application assessment).
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →