agentreadme

Report · marked 25 Aug 2026

usestrix/strix

Ready for an agent to work in without hand-holding.

Python · 58,166 stars · 467 files · branch main

Fix these first

01
File sizes fit in context
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
02
No committed build output
Add these to .gitignore and `git rm -r --cached` them. Generated files pollute search results, so an agent grepping for a function finds the compiled copy and edits the wrong file.
03
Pinned runtime version
Add a .nvmrc, .python-version, or equivalent so the agent's toolchain matches yours.

The full marking

Every deduction below names the file or setting it came from.

Instructions 27/27 A+

Whether the repo tells an agent how to behave before it starts guessing.

Agent instruction file 12/12
AGENTS.md is present, which is the format the most tools read.
Instruction quality 12/12
Specific enough that an agent can act on it.
3,724 characters, a workable length
names the actual commands to run
uses headings, so an agent can skim it
includes copyable code blocks
README as an entry point 3/3
README has a clear getting-started section.
Setup 12/14 A

Whether an agent can install the project and get it running without a human.

Deterministic install 6/6
uv.lock pins the dependency tree.
Found uv.lock
Discoverable commands 6/6
Commands are declared where an agent will look for them.
Makefile
pyproject.toml scripts
scripts/ directory
Environment config n/a
Not applicable — this reads as a library, with no environment to configure.
Pinned runtime version 0/2
No pinned runtime version.
Add a .nvmrc, .python-version, or equivalent so the agent's toolchain matches yours.
Reproducible environment n/a
Not applicable — a library doesn't need a container to be worked on.
Verification loop 24/25 A+

Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.

Tests exist 8/8
95 test files against 312 source files.
e.g. strix/interface/tui/internal/app/client_test.go, strix/interface/tui/internal/app/findings_test.go, strix/interface/tui/internal/app/frame_bench_test.go
Test command is discoverable 7/7
An agent can find and run `pytest`.
Continuous integration 4/4
1 GitHub Actions workflow define what "passing" means.
Lint and format rules 3/3
pyproject.toml encodes the house style.
Static type checking 2/3
Type checking is configured, but not in strict mode.
A type checker gives an agent an error message instead of a runtime surprise. It's the second-fastest feedback loop after the compiler.
Context economy 11/20 B-

Whether the repo fits in a context window, or fights it.

No committed build output 3/6
Generated output is committed: coverage/.
Add these to .gitignore and `git rm -r --cached` them. Generated files pollute search results, so an agent grepping for a function finds the compiled copy and edits the wrong file.
.gitignore hygiene 3/3
.gitignore covers 76 patterns.
File sizes fit in context 0/6
1 source file is over 100KB.
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
strix/interface/viewer/static/assets/index-C9c1WbvP.js — 947KB
Repository weight 5/5
About 12.5MB checked out, which is comfortable.

Here is your AGENTS.md

Drafted from what is actually in this repository: the install command from your lockfile, the commands you already declare, your real directory layout. Anything marked TODO needs a person. Save it at the root as AGENTS.md.

AGENTS.md — drafted for usestrix/strix
# AGENTS.md

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

## Setup

```
uv sync
```

## Commands

```
make help
make install
make dev-install
make setup-dev
make format        # format
make lint          # lint
```

## Layout

- `strix/`      227 source files
- `tests/`      80 source files
- `scripts/`    4 source files
- `containers/` 1 source file

## Conventions

- Tests live alongside the code they cover, following `strix/interface/tui/internal/app/client_test.go`.
- CI defines what passing means. See `.github/workflows/build-release.yml`, and keep it green.
- TODO: add the two or three conventions a newcomer always gets wrong here.

## Gotchas

- `strix/interface/viewer/static/assets/index-C9c1WbvP.js` is 947KB. It will not fit comfortably in context, so read it in parts.

---

Drafted by agentreadme.com from what is in this repository. Everything marked TODO
needs a human. Check it in as AGENTS.md at the root.

Open the raw markdown  or  curl -o AGENTS.md agentreadme.com/draft/usestrix/strix.md

Show the mark

The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.

agent ready 88 out of 100

[![agent ready](https://agentreadme.com/badge/usestrix/strix.svg)](https://agentreadme.com/usestrix/strix)

Other Python repositories, marked

vinta/awesome-python 81 A- NousResearch/hermes-agent 84 A- TheAlgorithms/Python 66 B yt-dlp/yt-dlp 54 C+ Significant-Gravitas/AutoGPT 63 B microsoft/markitdown 46 C

All Python repositories

Think this mark is wrong?

Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.

Open an issue, already filled in