web-app-penetration-testing
usestrix/strix
Black-box penetration testing of web apps with autonomous agents that validate every finding with a working exploit.
What is web-app-penetration-testing?
Strix performs end-to-end penetration testing of running web applications, staging environments, or local dev servers. It autonomously discovers and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each with a working proof-of-concept. Use this when you need to security-test or audit a web application.
- Discovers real vulnerabilities in running web apps via black-box testing
- Validates every finding with a working exploit proof-of-concept, eliminating false positives
- Tests across common vulnerability classes: auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic
- Accepts credentials and multi-account test scenarios to uncover authorization flaws
- Supports source-assisted testing when repository access is available for deeper coverage
- Generates detailed penetration test reports with per-finding exploit details
How to install web-app-penetration-testing
npx skills add https://github.com/usestrix/strix --skill web-app-penetration-testing- Strix CLI installed (self-hosted open-source or managed cloud account)
- Authorization to test the target application
- Target must be a running web application, staging environment, or local dev server
- Test credentials if the application requires authentication (recommended for comprehensive testing)
- LLM API key if using self-hosted CLI mode
How to use web-app-penetration-testing
- 1.Confirm you have authorization to test the target and define scope (in-scope paths, out-of-scope areas, credentials)
- 2.Run the scan with strix command, providing target URL and test credentials via --instruction flag
- 3.Optionally add source repository access (-t flag) for white-box depth on business logic
- 4.Review the penetration_test_report.md and per-finding vulnerability files in the output directory
- 5.Re-run the scan after fixes to validate that exploits no longer work
Use cases
- Security audit of a staging environment before production deployment
- Authorization and access-control testing across multi-tenant applications
- Vulnerability discovery in a development server during active development
- Pre-release security assurance testing with deep scan mode
- Continuous security scanning integrated into CI/CD pipelines
- Security engineers and penetration testers
- Development teams conducting internal security reviews
- DevSecOps engineers integrating security into CI/CD
- Product security managers preparing for external audits
- Developers testing their own applications before release
web-app-penetration-testing FAQ
Strix validates every reported vulnerability with a working exploit proof-of-concept rather than pattern matching. This eliminates false positives and proves real exploitability.
You can, but staging is preferred because agents send real exploit payloads and may create or modify data. Always confirm authorization first.
No, black-box testing works against any running URL. Adding source code (-t with a repo path) improves coverage of business-logic and authorization flaws.
Pass test credentials via the --instruction flag, including how to log in if the flow is unusual (magic link, SSO, MFA). Using two accounts is recommended to catch cross-account access vulnerabilities.
Each finding includes a working exploit proof-of-concept. Use the fix-security-vulnerabilities-with-strix skill to patch and re-run Strix to confirm the exploit no longer works.
Full instructions (SKILL.md)
Source of truth, from usestrix/strix.
name: web-app-penetration-testing description: Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site. license: Apache-2.0 metadata: author: usestrix homepage: https://docs.strix.ai
Pentest a web application
Black-box (and optionally source-assisted) penetration testing of a running web app with Strix's autonomous agents. Every reported finding is validated with a working exploit, so there are no signature-based false positives to triage.
Install, LLM setup, all CLI flags, and the managed-cloud alternative are covered in the penetration-testing-with-strix skill — read it if the target is not a running web app, or if strix --version fails. For a run with no Docker and no LLM key, the same binary drives the managed platform: strix cloud login, then strix cloud scans start ... (details in managed-pentesting-with-strix). This skill is the web-app-specific workflow.
1. Confirm authorization and scope
Before running anything, establish:
- The target is the user's (or they are explicitly authorized to test it). Never pentest a third-party site on a hunch.
- Which environment. Prefer staging over production; agents send real exploit payloads and will create/modify data.
- Out-of-scope paths — payment flows, mass-email endpoints, admin destructive actions, third-party SSO providers.
- Credentials. Most real vulnerabilities live behind login. Without a test account, the agents only ever see the marketing surface.
Ask for anything missing rather than guessing.
2. Run the scan
strix -n -t https://staging.example.com --max-budget 20 \
--instruction "Test account: qa@example.com / <password>. In scope: /app/*, /api/*. Do not touch /billing or send email. Focus on access control between the two seeded orgs."
Notes that matter for web apps specifically:
- Give it credentials via
--instruction(or--instruction-filefor anything long), including how to log in if the flow is unusual (magic link, SSO, MFA-exempt test user). - Two accounts beat one. Multi-tenant IDOR and broken-access-control bugs — consistently the highest-impact class in web apps — can only be proven when the agent can attempt cross-account access.
- Add the repo for white-box depth when you have the source:
-t https://github.com/org/app -t https://staging.example.com(or a local path). Source access materially improves coverage of business-logic and authorization flaws. - Localhost works. Point at
http://host.docker.internal:3000(Docker Desktop) so the sandbox can reach a dev server on the host. --scan-mode quickfor a fast dev-loop pass,standard(~30 min) for a normal review,deepfor pre-release assurance. Always set--max-budget.
For a hosted run with no Docker/LLM key, or when the user wants a shareable dashboard and an auditor-ready PDF, use the cloud path in managed-pentesting-with-strix instead — same engine, same findings.
3. Review results
Read strix_runs/<run>/penetration_test_report.md first, then per-finding files in vulnerabilities/. Each contains the PoC — re-run it yourself to confirm before reporting to the user.
Exit codes: 0 no validated vulns in what was analyzed, 2 vulnerabilities found, 1 fatal error. A 0 is not proof of full coverage — if the budget or turn cap was hit the scan wraps up early, so check run.json status and cost against --max-budget before calling the app clean.
4. Fix and verify
Hand findings to the fix-security-vulnerabilities-with-strix skill: patch the root cause, then re-run Strix against the same target to prove the exploit no longer works. Re-testing is the only reliable confirmation a fix landed.
To keep the app tested on every change rather than once, wire Strix into CI with ci-security-scanning-with-strix.
Related skills
More from usestrix/strix and the wider catalog.

api-security-testing
Autonomously exploit OWASP API Security Top 10 vulnerabilities—BOLA, broken authorization, SSRF, injection—with proof-of-concept requests.

application-security-testing
Autonomous security testing across code, APIs, and live apps—ranked by proven exploitability.

ci-security-scanning-with-strix
AI-powered security scanning for CI/CD pipelines — block vulnerable code before merge.

find-security-vulnerabilities-in-code
White-box security review with proof-of-concept exploits, not static-analysis noise.

valyu-best-practices
Complete Valyu API toolkit for real-time search, content extraction, and AI-powered research across web, academic, and financial sources.

drama-creator
创作竖屏短剧剧本,包括宏观建构、剧本创作、精准优化、创意发想。适用于从零开始创作短剧、优化现有剧本、设计故事大纲和悬念钩子