v1.6.0Android
Added 14
- Place caller-provided files into the sandbox workspace via extra_files and --workspace-file
- Add contextual CVSS breakdown on dependency reports
- Add OWASP LLM Top 10 2026 skill coverage
- Add Azure and Entra security skill
- Add argument injection security skill
- Add ecosystem supply-chain security skills
- Add Hurl and Hypothesis security playbooks
- Add semantic browser and Electron security skills
- Expose viewer host option
- Add evidence discipline and coverage as a first-class artifact in agents
- Add MCP server support
- Add strix cloud — managed platform CLI for login, scans, billing, and API
- Add pentest skill cloud CLI
- Add update_vulnerability_report so an agent can revise a filed finding
Changed 11
- Require contextual CVSS and usage evidence on dependency reports
- Drop strict tool schemas on Claude routes
- Improve skills
- Take heavy imports off the startup path and pre-warm them in the background
- Bootstrap Caido concurrently with the scan start
- Treat literal 'null' and 'none' strings as absent for optional tool arguments
- Scope threat models to the current run instead of caching them on disk
- Reach MCP tools on demand instead of registering every one
- Isolate MCP connections per task and surface connection status in the UIs
- Make MCP connections survive transient transport failures
- Forward the workspace header through CLI
Fixed 13
- Fix LiteLLM cost model resolution
- Handle resume tokens gracefully
- Preserve cost in TUI when state is truncated
- Use single space after ordered-list marker in TUI
- Raise RuntimeError on non-object run.json in report
- Re-exec runs the new binary after self-update to prevent endless update-prompt loop
- Restore base foreground after ANSI resets in TUI
- Only attach prompt-cache points on routes LiteLLM serves
- Bind dedupe credentials to a provider and send reasoning=max via extra_body
- Keep strix.report import-light to prevent races with the warm-up thread
- Fix user message retry lifecycle and TUI sync
- Harden PDF report rendering in viewer
- Stage extra-file bind mounts where a remote docker daemon can see them
Security 1
- Add CSV injection hardening
From strix
What's Changed
- Fix LiteLLM cost model resolution by @bearsyankees in https://github.com/usestrix/strix/pull/1069
- feat: place caller-provided files into the sandbox workspace (
extra_files,--workspace-file) by @yoni-at-strix in https://github.com/usestrix/strix/pull/1085 - feat(reporting): contextual CVSS breakdown on dependency reports by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1091
- feat(reporting): require contextual CVSS and usage evidence on dependency reports by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1092
- handle resume tokens gracefully by @bearsyankees in https://github.com/usestrix/strix/pull/1097
- Add OWASP LLM Top 10 2026 skill coverage by @bearsyankees in https://github.com/usestrix/strix/pull/1115
- Add Azure and Entra security skill by @bearsyankees in https://github.com/usestrix/strix/pull/1119
- Add argument injection security skill by @bearsyankees in https://github.com/usestrix/strix/pull/1120
- Add ecosystem supply-chain security skills by @bearsyankees in https://github.com/usestrix/strix/pull/1121
- Add Hurl and Hypothesis security playbooks by @bearsyankees in https://github.com/usestrix/strix/pull/1122
- Add semantic browser and Electron security skills by @bearsyankees in https://github.com/usestrix/strix/pull/1123
- Expose viewer host option by @kusonooyasumi in https://github.com/usestrix/strix/pull/1127
- Drop strict tool schemas on Claude routes by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1136
- fix(tui): preserve cost when state is truncated by @kusonooyasumi in https://github.com/usestrix/strix/pull/1086
- fix(tui): use single space after ordered-list marker by @OpenPay-App in https://github.com/usestrix/strix/pull/1043
- fix(report): raise RuntimeError on non-object run.json (fixes #1109) by @vardhans07 in https://github.com/usestrix/strix/pull/1116
- better skills by @bearsyankees in https://github.com/usestrix/strix/pull/1139
- perf: take heavy imports off the startup path and pre-warm them in the background by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1141
- perf: bootstrap Caido concurrently with the scan start by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1143
- feat(agents): evidence discipline, and coverage as a first-class artifact by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/961
- Add MCP server support by @yoni-at-strix in https://github.com/usestrix/strix/pull/1137
- Treat literal 'null'/'none' strings as absent for optional tool args by @bearsyankees in https://github.com/usestrix/strix/pull/1164
- fix(update): re-exec runs the new binary after self-update (endless update-prompt loop) by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1168
- fix(tui): restore base foreground after ANSI resets by @bearsyankees in https://github.com/usestrix/strix/pull/1169
- Scope threat models to the current run instead of caching them on disk by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1178
- Reach MCP tools on demand instead of registering every one by @yoni-at-strix in https://github.com/usestrix/strix/pull/1175
- Isolate MCP connections per task and surface connection status in the UIs by @yoni-at-strix in https://github.com/usestrix/strix/pull/1181
- fix(llm): only attach prompt-cache points on routes LiteLLM serves by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1186
- fix(llm): bind dedupe credentials to a provider; send reasoning=max via extra_body by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1187
- fix(report): keep strix.report import-light so it never races the warm-up thread into the agents SDK graph by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1188
- Fix user message retry lifecycle and TUI sync by @0xallam in https://github.com/usestrix/strix/pull/1193
- csv injection hardening by @bearsyankees in https://github.com/usestrix/strix/pull/1203
- fix(viewer): harden PDF report rendering by @kusonooyasumi in https://github.com/usestrix/strix/pull/1192
- fix(runtime): stage extra-file bind mounts where a remote docker daemon can see them by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1211
- Make MCP connections survive transient transport failures by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1184
- feat(cli): strix cloud — managed platform CLI (login, scans, billing, and the rest of the API) by @bearsyankees in https://github.com/usestrix/strix/pull/1177
- pentest skill cloud cli by @bearsyankees in https://github.com/usestrix/strix/pull/1220
- Forward the workspace header through cli by @bearsyankees in https://github.com/usestrix/strix/pull/1221
- report: add update_vulnerability_report so an agent can revise a filed finding by @bearsyankees in https://github.com/usestrix/strix/pull/1210
- chore: release v1.6.0 by @devin-ai-integration[bot] in https://github.com/usestrix/strix/pull/1223
New Contributors
- @OpenPay-App made their first contribution in https://github.com/usestrix/strix/pull/1043
- @vardhans07 made their first contribution in https://github.com/usestrix/strix/pull/1116
Full Changelog: https://github.com/usestrix/strix/compare/v1.5.3...v1.6.0