Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Strix 快速安全评估模式,面向高影响漏洞的限时测试;触发名:strix-quick
.claude/skills/asdfgh1445-strix-4aa6aa/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 10% | 0% |
| case-05 | ✓→✗ | ▼ Worse | -83% | 0% |
| case-14 | ✓→✗ | ▼ Worse | 25% | 0% |
| case-11 | ✓→✓ | = Same ✓ | 46% | 0% |
Time-boxed assessment focused on high-impact vulnerabilities. Prioritize breadth over depth.
Optimize for fast feedback on critical security issues. Skip exhaustive enumeration in favor of targeted testing on high-value attack surfaces.
Whitebox (source available)
wiki notes first (list_notes(category="wiki") then get_note(note_id=...)) to avoid remapping from scratchsemgrep, then targeted sg queries)sg or Tree-sitter) so structural mapping is not skippedgitleaks, trufflehog, trivy fs) scoped to changed areas when possibleBlackbox (no source)
Test in priority order:
Skip for quick scans:
When a strong primitive is found (auth weakness, injection point, internal access), immediately attempt one high-impact pivot to demonstrate maximum severity. Don't stop at a low-context "maybe"—turn it into a concrete exploit sequence that reaches privileged action or sensitive data.
Think like a time-boxed bug bounty hunter going for quick wins. Prioritize breadth over depth on critical areas. If something looks exploitable, validate quickly and move on. Don't get stuck—if an attack vector isn't yielding results quickly, pivot.
Other measured skills in the registry, with their headline benchmark lift.