88OUT OF 100
Likely safeLikely safeStatic read

usestrix/strix

Strix is a well-established open-source security tool with a high reputation. The flagged network activities are consistent with its documented installation process and internal container orchestration. No malicious behavior was observed in our static read; full runtime behavior was not executed in a sandbox on this pass.

Repository size
13889 KB
Packages
0
Stars
62496
Created
676 days
Reputation signals
usestrix avatar
Strix
@usestrix
Account age1 yr 10 mo
Public repos3
Forks6.8k
Community sentiment95

High

Code & behavior signals
Installation network fetch
LowBehavior

The README and install scripts utilize curl to fetch installation components from strix.ai and GitHub APIs, which aligns with the declared installation intent.

Internal container proxy configuration
LowCode

Hardcoded loopback addresses (127.0.0.1) in docker-entrypoint.sh are used for local proxy and service health checks, which is standard for containerized infrastructure.

Per-package scoring
Final verdict

No malicious behavior in our static read. The caveats above are worth noting and the owner is not yet long-established. Runtime was not executed in a sandbox on this pass.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully
›Commit hash verified: 84f4108195fb516d48745aa912ba8862c7360ebb
Static scan
›No obfuscation or credential access patterns detected
›Network activity identified as standard installation and local service orchestration
Reputation
›Owner 'usestrix' is highly established with 62k+ stars
›Project is a widely recognized security tool
Read
›README intent matches installation script behavior
›Container entrypoint logic confirmed as local infrastructure management
Score
›Score computed by formula: 88/100 (deterministic, code-driven)
›-6 [code] network: Code has outbound network capability (fetch / child_process / hardcoded IP URL).
›-6 [code] model_findings: 2 code/behavior finding(s) reported by the read model.
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+6 [reputation] many_stars: Strong community signal (62,496 stars).
›+4 [reputation] good_sentiment: Positive community sentiment (95/100).
Auto-published at clauderabbit.in/usestrix/strix · re-checked when the repo changes