ci-security-scanning-with-strix

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes instructions to install the Strix CLI using a piped shell script: curl -sSL https://strix.ai/install | bash. This installation script is hosted on the official domain of the tool vendor.
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads resources from the vendor's infrastructure (strix.ai) to facilitate the setup of security scanning services.
  • [COMMAND_EXECUTION]: Provides various shell commands and workflow configurations to execute the strix CLI for local scans and to interact with the managed cloud platform for PR reviews.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly advises users to store sensitive credentials, such as LLM_API_KEY and STRIX_API_TOKEN, as environment secrets within their CI/CD platform (e.g., GitHub Secrets), which is a standard security best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:35 AM
Security Audit — agent-trust-hub — ci-security-scanning-with-strix