ci-security-scanning-with-strix
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill includes instructions to install the Strix CLI using a piped shell script:
curl -sSL https://strix.ai/install | bash. This installation script is hosted on the official domain of the tool vendor. - [EXTERNAL_DOWNLOADS]: The skill references and downloads resources from the vendor's infrastructure (
strix.ai) to facilitate the setup of security scanning services. - [COMMAND_EXECUTION]: Provides various shell commands and workflow configurations to execute the
strixCLI for local scans and to interact with the managed cloud platform for PR reviews. - [CREDENTIALS_UNSAFE]: The documentation explicitly advises users to store sensitive credentials, such as
LLM_API_KEYandSTRIX_API_TOKEN, as environment secrets within their CI/CD platform (e.g., GitHub Secrets), which is a standard security best practice.
Audit Metadata