Instagram · 13 Aug 2026
View the original on instagram.comTopicAI security testing tool
AI security testing tool
By @heystevetan · Instagram
Source: https://www.instagram.com/reel/Db8UlykziRz/?igsh=aDNpYmY3emI3d3M=
AI generated summary of the linked source. Posted anonymously. Transcripts are published only for public links, never for uploads, documents or pasted text.
Share
The AI link is plain markdown. Paste it into any assistant and it can read the whole public entry.
Summary
Strix is a free tool that acts like a real attacker on your vibe coded app, finding security holes and handing you the exact fix. It replaces the manual verification step most builders skip, and it costs a few dollars to run on your own model key instead of thousands from a security firm.
Core ideas
- Behavioral testing over code scanning: A normal scanner just reads your code and flags anything that looks risky. Strix actually logs in, clicks around, and tries to reach places it shouldn't, which is a completely different test.
- Finds real world exploits: It catches things like a page where one customer can see another customer's data, the exact kind of bug that normally surfaces through an angry email instead of a report.
- Comes with a patch, not just a warning: Strix returns the exact steps that broke the app plus a patch you can apply, so there's nothing left for you to manually verify.
- Runs on your own infrastructure: It installs on your machine and runs using your own model key, so you control the cost and the environment.
- Cheap compared to hiring a firm: A run costs a few dollars instead of the thousands security firms typically charge for this kind of testing.
- Spend cap matters: Since it runs on your own key, setting a spend cap flag before the first run keeps costs predictable.
- Give it time to work: The first run should be given an evening, not a quick five minute check.
- Ownership is a legal boundary: Point it only at apps you own. Running it against someone else's site is a crime.
Quotes
“vibe coded apps had one big problem and this free tool just fixed it”
“this repo installs on your machine runs your app the way a customer would and then it attacks it”
“a scanner reads your code and flags anything that looks risky strix actually logs in and clicks around trying to get where it should not be”
“that is the kind of thing you usually find out about from an angry email”
“running it on someone else's site is a crime”
Resources
Links to the tools, products, repos or reading this entry mentions. Found by a web search of what the entry names, so you can go and use them.
- naohmsmedia.com
naohmsmedia.com
- simplicable.com
simplicable.com
- salesforce.com
salesforce.com
Remix this knowledge
Turn this entry into something you can post. Pick a format and get a fresh, original rewrite.
Remixes are AI generated, original wording, and free to reuse.
Talk it through
Open a round table on this entry and argue with other people about what it means.
Start a round tableDrop your own
Paste any video, podcast or audio link and get the transcript, the core ideas and the quotes back in one pass.
Try Drop