web-app-penetration-testing
usestrix/strixPentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real…
Scores out of 100 · grade A
2026-08-22Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score65/100
- 56,804 stars on the source repo.
Documented
15% of the score66/100
- 506 words with worked examples.
Install
npx skills add usestrix/strix/web-app-penetration-testingWhat it says it does
Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.
Also in usestrix/strix
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| ci-security-scanning-with-strixusestrix/strix | clean | Skill | 3,244 installs | today | |
| managed-pentesting-with-strixusestrix/strix | clean | Skill | 3,225 installs | today | |
| find-security-vulnerabilities-in-codeusestrix/strix | clean | Skill | 57k stars | today | |
| fix-security-vulnerabilities-with-strixusestrix/strix | clean | Skill | 3,314 installs | today | |
| owasp-top-10-testingusestrix/strix | clean | Skill | 57k stars | today | |
| application-security-testingusestrix/strix | clean | Skill | 57k stars | today |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=usestrix%2Fstrix)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
