penetration-testing-with-strix

Fail

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill suggests installing the Strix agent by piping a remote script directly to the bash shell: curl -sSL https://strix.ai/install | bash. This pattern is highly risky as it executes remote code from an external source with the user's current privileges, bypassing package manager security checks and signature verification.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the strix CLI, which performs complex operations including Docker container management and automated security scanning of local and remote targets.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and exploit vulnerabilities in external targets, which creates a significant attack surface for indirect prompt injection if those targets contain malicious instructions.
  • Ingestion points: Target URLs, public git repositories, and local code directories provided through the -t or --target-list flags.
  • Boundary markers: The skill's instructions do not include boundary markers or guidance for the agent to ignore instructions found within target data.
  • Capability inventory: The strix tool has extensive capabilities, including network communication and the ability to modify files in the local workspace when a local path is mounted into its sandbox.
  • Sanitization: There is no mention of sanitization or filtering logic applied to the content retrieved from the targets before it is processed by the AI agents.
Recommendations
  • HIGH: Downloads and executes remote code from: https://strix.ai/install - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 4, 2026, 02:39 AM
Security Audit — agent-trust-hub — penetration-testing-with-strix