nyxstrike

作者 CommonHuman-Lab已验证

AI Powered penetration testing Platform for offensive security research

142
Stars
35
Forks
Python
语言
2026/8/23
添加时间

⚠️ 第三方软件声明

本 Skill 为第三方开源软件,独立托管于 GitHub。SkillTip 仅为信息目录,不控制或维护底层仓库。所显示的安全检查为自动化且范围有限,安装前请自行审查源码。

阅读服务条款

安装

添加到你的 Claude Code skills 目录:

# Add to your Claude Code skills
git clone https://github.com/CommonHuman-Lab/nyxstrike

快速入门

使用 nyxstrike 等 Skills 的指南。

安全报告

已验证

上次扫描:—

{
  "status": "PASSED",
  "issues": []
}

README.md

NyxStrike

NyxStrike

AI-powered offensive security orchestration engine

What is NyxStrike?

NyxStrike connects LLM agents to real offensive security tools and executes full attack chains — from recon to exploitation.

200+ tools · 50+ categories · AI decision engine · Tamper-evident evidence chain


🚀 Quick Start (Installation)

Get a full offensive security environment running in minutes.

git clone https://github.com/CommonHuman-Lab/nyxstrike.git
cd nyxstrike

./nyxstrike.sh -a               # Setup + start server
./nyxstrike.sh -a -t            # + install external tools

Full flag reference: Wiki — Installation & Flags

Verify Setup

Open http://localhost:8888 to access the dashboard.

Some tools (e.g. nmap, masscan) require elevated privileges for specific scan modes. Use a dedicated test VM and least-privilege setup where possible.


🔌 AI Agent Integrations (MCP)

Connect NyxStrike to any MCP-compatible AI client — OpenCode, Cursor, Claude Desktop, VS Code Copilot, Roo Code, and more.

Open http://localhost:8888/#/help for help with configurations.

Universal MCP Command

/path/to/nyxstrike/nyxstrike-env/bin/python3 \
  /path/to/nyxstrike/nyxstrike_mcp.py \
  --server http://127.0.0.1:8888 \
  --profile full

OpenCode

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "nyxstrike": {
      "type": "local",
      "command": [
        "/path/to/nyxstrike/nyxstrike-env/bin/python3",
        "/path/to/nyxstrike/nyxstrike_mcp.py",
        "--server",
        "http://127.0.0.1:8888",
        "--profile",
        "full"
      ],
      "enabled": true
    }
  }
}

Config snippets for Claude Desktop, Cursor, VS Code Copilot, and security options: Wiki — MCP Setup


🔧 Features

NyxStrike does not just run tools — it orchestrates full attack chains using AI decision-making.

  • AI agents that chain tools automatically, guided by a decision engine that ranks and re-scores tools mid-scan
  • 200+ offensive security tools, all agent-controllable
  • Full attack workflow: recon → enumeration → exploitation → reporting
  • Local payload & data workbench — 40+ crypto, encoding, and analysis operations, no target required
  • Every tool run hash-chained for tamper-evident, verifiable evidence
  • Real-time dashboard — live output, network topology maps
  • MCP-compatible — plug into any AI client you already use

Full feature breakdown · Session & workbench docs


🧰 Tool Arsenal

200+ offensive security tools across 50+ categories — all dynamically orchestrated by AI agents in real time.

  • Network & wireless reconnaissance
  • Web & API exploitation
  • OSINT & intelligence gathering
  • Password & credential attacks
  • Binary exploitation & reverse engineering
  • Cloud, container & IaC security
  • Digital forensics & incident response

Full tool list by category


⚠️ Security Considerations

NyxStrike gives AI agents direct access to offensive security tooling.

  • Run only in isolated environments or dedicated security testing VMs
  • AI agents may execute real commands — maintain operator oversight
  • Monitor activity via dashboard and logs in real time
  • Use NYXSTRIKE_API_TOKEN for any non-local deployment

Legal & Ethical Use

AllowedNot Allowed
Authorized penetration testing (with written authorization)Unauthorized testing of any system
Bug bounty programs (within program scope and rules)Malicious, illegal, or harmful activities
CTF competitions and educational environmentsUnauthorized data access or exfiltration
Security research on owned or authorized systems
Red team exercises (with organizational approval)

📜 License

Licensed under the AGPLv3. You are free to use, modify, and distribute this software. If you run it as a service or distribute it, the source must remain open.

For commercial licensing, contact the author.


⭐ Support the project

If NyxStrike is useful to your workflow:

  • Star the repository
  • Share it with others
  • Contribute improvements

It makes a real difference.


Credits

Originally inspired by hexstrike-ai.

常见问题

What is nyxstrike?

nyxstrike is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by CommonHuman-Lab. AI Powered penetration testing Platform for offensive security research. It has 142 GitHub stars.

Is nyxstrike safe to use?

Yes. nyxstrike passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.

How do I install nyxstrike?

Clone the repository with "git clone https://github.com/CommonHuman-Lab/nyxstrike" and add it to your Claude Code skills directory (see the Installation section above).

What programming language is nyxstrike written in?

nyxstrike is primarily written in Python. It is open-source under CommonHuman-Lab on GitHub, so you can review or fork the full source.

Are there alternatives to nyxstrike?

Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh nyxstrike against similar tools.

评论 (0)

暂无评论,成为第一个分享想法的人!

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP 服务器apisai-tools
查看详情

Scrapling

by D4Vinci

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

75,9137,581Python
MCP 服务器
查看详情

TrendRadar

by sansan0

⭐AI-driven public opinion & trend monitor with multi-platform aggregation, RSS, and smart alerts.🎯 告别信息过载,你的 AI 舆情监控助手与热点筛选工具!聚合多平台热点 + RSS 订阅,支持关键词精准筛选。AI 智能筛选新闻 + AI 翻译 + AI 分析简报直推手机,也支持接入 MCP 架构,赋能 AI 自然语言对话分析、情感洞察与趋势预测等。支持 Docker ,数据本地/云端自持。集成微信/飞书/钉钉/Telegram/邮件/ntfy/bark/slack 等渠道智能推送。

61,65224,883Python
MCP 服务器
查看详情

context7

by upstash

Context7 Platform -- Up-to-date code documentation for LLMs and AI code editors

61,0602,938TypeScript
MCP 服务器
查看详情

High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.

39,9393,219C
MCP 服务器
查看详情

开发者还喜欢

基于喜欢此 Skill 的开发者投票和收藏

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI 智能体ai-agentsbrainstorming
查看详情

hermes-agent

by NousResearch

10

The agent that grows with you

234,43747,175Python
AI 智能体ai-agentsagent-orchestration
查看详情

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP 服务器apisai-tools
查看详情

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI 智能体claude-codeai-tools
查看详情