Strix 是开源 AI pentesting 工具,README 称其 autonomous agents 会像真实攻击者一样动态运行代码、找漏洞并用 PoC 验证。能力清单包括 reconnaissance、exploitation、validation、多 agent orchestration、developer-first CLI、auto-fix 和 compliance-ready reports。它还提供 GitHub Actions/CI 集成,用于在 pull request 阶段扫描并阻断不安全代码;关键差异是“验证可利用性”,而不是只输出静态扫描告警。
–浏览
评论 · Comments