skills/ci-security-scanning-with-strix/SKILL.md
You can gate PRs two ways — pick based on the environment, or combine them:
Both fail the build on validated findings and both emit SARIF 2.1.0, so you can start with one and add the other later.
Run a diff-scoped Strix scan on every PR: only changed files are tested, quick mode keeps it fast, and exit code 2 fails the build when validated vulnerabilities are found.
Create .github/workflows/security.yml:
name: Security Scan
on:
pull_request:
jobs:
strix-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # required for diff-scope resolution
- name: Install Strix
run: curl -sSL https://strix.ai/install | bash
- name: Run Security Scan
env:
STRIX_LLM: ${{ secrets.STRIX_LLM }}
LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
run: strix -n -t ./ --scan-mode quick --max-budget 10
# Don't fail open: a run that hits the hard budget stop exits 0 but leaves
# run.json status "stopped", not "completed". Enforce completion explicitly.
# This does not catch an agent that wrapped up early on a budget *warning*
# (it still calls finish_scan and records "completed"), so size the budget.
- name: Fail unless the scan completed
run: |
run_json=$(ls -t strix_runs/*/run.json | head -1)
status=$(jq -r .status "$run_json")
if [ "$status" != "completed" ]; then
echo "Strix run status is '$status' — the scan did not complete (likely budget exhausted). Raise --max-budget." >&2
exit 1
fi
Then tell the user to add two repository secrets: STRIX_LLM (model id, for example openai/gpt-5.4) and LLM_API_KEY (the provider key). Do not create these values yourself.
Notes:
--scope-mode auto). If diff resolution fails, keep fetch-depth: 0 or set --diff-base to the PR's actual base branch — use origin/${{ github.base_ref }} in GitHub Actions rather than a hard-coded origin/main, since repos use different default branches.0 pass, 2 vulnerabilities found (fails the job), 1 setup error.0 exit means "no validated vulnerabilities in what was analyzed"; if --max-budget is hit before the diff is fully covered, the scan wraps up early and can still exit 0. The "Fail unless the scan completed" step above narrows the gap: strix_runs/<run>/run.json is "stopped" when the scan was cut off at the hard budget limit without a final report. It is not a complete guard — the agents get graduated wrap-up warnings before that limit, and a run that wraps up on a warning still calls finish_scan and records "completed" with partial coverage. So keep that step in any pipeline that gates merges and give the scan real headroom (compare run.json's llm_usage.cost against --max-budget; if it ran right up to the cap, raise it). For a quick diff-scoped PR scan --max-budget 10 is usually ample, raise it for large diffs.Strix writes SARIF 2.1.0 to strix_runs/<run>/findings.sarif:
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: strix_runs
Any pipeline works the same way — install, set the two env vars, run headless:
curl -sSL https://strix.ai/install | bash
# Resolve the PR's base branch robustly (use your CI's base-branch variable if it
# has one, for example GitHub Actions: origin/${{ github.base_ref }}). Avoid piping the
# git lookup into another command — a failed lookup would otherwise be masked.
BASE_BRANCH="${CI_MERGE_REQUEST_TARGET_BRANCH_NAME:-}" # GitLab MR target
if [ -z "$BASE_BRANCH" ]; then
BASE_BRANCH=$(git symbolic-ref --quiet --short refs/remotes/origin/HEAD 2>/dev/null)
BASE_BRANCH="${BASE_BRANCH#origin/}"
fi
DIFF_BASE="origin/${BASE_BRANCH:-main}"
# Fail loudly rather than silently narrowing scope (for example, to HEAD~1, which on a
# multi-commit branch would scan only the last commit and let earlier ones pass).
if ! git rev-parse --verify --quiet "$DIFF_BASE" >/dev/null; then
echo "Cannot resolve diff base '$DIFF_BASE'. Fetch the base branch (git fetch origin <base>) or set --diff-base explicitly." >&2
exit 1
fi
strix -n -t ./ --scan-mode quick --scope-mode diff --diff-base "$DIFF_BASE" --max-budget 10
Gate the pipeline on the exit code (see the budget/fail-open caveat above — give the scan enough budget to finish). Schedule standard scans nightly and deep scans for release candidates.
No workflow file, no Docker, no LLM key. Three ways to use it:
PR-review app (zero code): the user installs the Strix GitHub/GitLab/Bitbucket app and enables PR reviews for the repo in the app.strix.ai dashboard. Every PR is then reviewed automatically, with findings posted as PR comments. Nothing to add to the repo. This is the lowest-effort path — recommend it first when the user just wants PR gating.
CLI-triggered from any pipeline: if you want to trigger from an existing pipeline (or a system without the SCM app), use the same strix binary with a token that has pr_reviews:write. Store the token as a CI secret and ask the user to create it at Settings → API Access. Read the repository's provider and installation_id once with strix cloud repos list. Example GitHub Actions step:
- name: Strix PR review (managed)
if: github.event_name == 'pull_request'
env:
STRIX_API_TOKEN: ${{ secrets.STRIX_API_TOKEN }}
run: |
curl -sSL https://strix.ai/install | bash
strix cloud pr-reviews start \
--provider github \
--installation-id "${{ vars.STRIX_INSTALLATION_ID }}" \
--repository-full-name "${{ github.repository }}" \
--pr-number "${{ github.event.pull_request.number }}"
Output is JSON when stdout is not a terminal, and there are no prompts without a TTY. To gate the build on results, poll strix cloud pr-reviews get <id> --json and fail on unresolved criticals or highs. The raw REST endpoint (POST /api/v1/pr-reviews/start) works too when the pipeline cannot install the CLI.
Source upload from a pipeline without an SCM app: upload the checked-out tree as a cloud code review (scans:write and uploads:write). The two-step digest handoff keeps a human in control of what leaves the runner:
strix cloud scans start --source . --dry-run --show-files --json # review, capture source.archive_sha256
strix cloud scans start --source . --approve-sha256 "$SOURCE_SHA256" --wait
Exit codes: 0 success, 4 auth or plan limit, 5 payment required. Non-Enterprise scans consume credits.
Full CLI coverage (PR reviews, scans, SARIF export, schedules) is in the managed-pentesting-with-strix skill.
Recommend Option B for most teams (no maintenance, central dashboard); use Option A when scans must stay entirely within your own infrastructure.