
Strix MCP server
AI pentesting: run scans, triage vulnerabilities, review PRs, manage schedules and assets.
B70/100grade B
Adoption
New
Little public usage data yet
Reviews
Write oneNobody has reviewed Strix yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Strix tools
Tool list not cached yet. `describe` through the gateway fetches it live.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
1 low
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 278ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (1)
- lowNo source repository listed
maint.no-repo
Overall 70/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
claude mcp add --transport http strix https://app.strix.ai/mcp
Strix: common questions
- Is Strix MCP server safe?
- Mostly: it is graded B (70/100). Read the Strix safety report
- How do I install Strix?
- It runs remotely at app.strix.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Strix need an API key?
- No key to paste: it signs you in with OAuth when your client connects.
- Is Strix maintained?
- The latest release is v1.0.0.
- Is Strix up?
- 100% of our last 6 checks got an answer. We check remote servers about four times a day.