managed-pentesting-with-strix
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous
curlandjqexamples for interacting with the Strix REST API. These are benign and follow standard documentation patterns for API integration. - [EXTERNAL_DOWNLOADS]: The skill references official Strix documentation (
docs.app.strix.ai) and the OpenAPI specification (docs.app.strix.ai/openapi.json). These are trusted resources belonging to the skill's authoring vendor, usestrix. - [CREDENTIALS_UNSAFE]: The skill correctly instructs users to store their API tokens in environment variables (
STRIX_API_TOKEN) or CI secret stores. It explicitly warns against hardcoding, logging, or committing tokens. - [SAFE]: The skill includes a dedicated 'Safety' section emphasizing that users must only scan authorized assets and that the platform enforces domain verification to prevent unauthorized testing.
Audit Metadata