## usestrix/strix — v1.5.3…v1.6.0

_55 commits._

### Features
- **report: add update_vulnerability_report so an agent can revise a filed finding (#1210)** (46cf2f5)
- **feat(cli): strix cloud — managed platform CLI (login, scans, billing, and the rest of the API) (#1177)** (de73011)
- **Add MCP server support (#1137)** (f4ef886)
- **feat(agents): evidence discipline, and coverage as a first-class artifact (#961)** (391d81b)
- **feat(skills): add target-specific security testing skills (web app, API, OWASP Top 10, code review)** (b5ef93e)
- **New security skills for browsers and Electron** — Added comprehensive security analysis skills for semantic confusion vulnerabilities (parser/normalization mismatches across components), browser security testing (postMessage, XS-Leaks, service workers), and Electron desktop app vulnerabilities (renderer-to-native boundaries, IPC exposure). Also enhanced existing vulnerability documentation with cross-component semantic mapping guidance. (9cd81e5)
- **New HTTP testing documentation added** — Added guides for Hurl and Hypothesis, two tools for differential HTTP testing and security regression validation. These resources document how to write reproducible HTTP request chains, capture values, assert on responses, and design security test cases. (e8272c6)
- **Add supply-chain security skills** — Added four new security assessment capabilities covering npm package confusion attacks, agentic system security, infrastructure lifecycle risks, and related supply-chain vulnerabilities. These skills expand the platform's ability to detect and analyze modern software supply-chain attack vectors. (aa5867f)
- **Add argument injection security skill** — A new security analysis skill for detecting argument injection vulnerabilities has been added, covering shell-free CLI option smuggling, secondary argument-file parsing, and platform-specific argv transformation boundaries. (7b8f9cb)
- **Add Azure security analysis skill** — Added a new security skill for analyzing Azure and Microsoft Entra environments, covering privilege escalation, PIM (Privileged Identity Management), workload identity, and cross-plane attack scenarios. This skill enables security assessments specific to Azure cloud infrastructure. (2d944a9)
- **Add OWASP LLM Top 10 2026 coverage** — Added comprehensive LLM security skills covering OWASP 2026 LLM vulnerabilities (LLM01-LLM10) across models, RAG systems, vectors, agents, and tools, plus expanded prompt injection testing to include direct, indirect, multimodal, and memory-based attacks. (0478a69)
- **Require CVSS context on dependency reports** — Dependency vulnerability reports now mandate a contextual CVSS breakdown and reasoning for every finding, even when the published score applies directly. The tool rejects reports missing reachability evidence or contextual CVSS fields, ensuring all dependency vulnerabilities include the codebase-specific risk assessment and clear evidence trails. (a46a60c)
- **feat(reporting): contextual CVSS environmental metrics on dependency reports** (310f310)
- **feat: place caller-provided files into the sandbox workspace (`extra_files`, `--workspace-file`) (#1085)** (8551339)

### Fixes
- **fix(runtime): drop staged extra files on any failure before the bundle is cached** (f901d2a)
- **fix(runtime): remove the extra-file staging dir on cleanup and failed bring-up** (944274e)
- **fix(runtime): stage extra-file bind mounts under the temp dir so remote docker daemons can resolve them** (eeca404)
- **fix(viewer): harden PDF report rendering (#1192)** (1df67c5)
- **Fix user message retry lifecycle and TUI sync** (0a6e8b0)
- **fix(report): keep strix.report import-light so it never races the warm-up thread into the agents SDK graph** (1f3f9b3)
- **fix(llm): bind dedupe credentials to a provider; send reasoning=max via extra_body (#1187)** (cf179d5)
- **fix(llm): only attach prompt-cache points on routes LiteLLM serves (#1186)** (583af23)
- **fix(tui): restore base foreground after ANSI resets (#1169)** (a585610)
- **fix(update): re-exec runs the new binary after self-update (endless update-prompt loop) (#1168)** (bfaaa90)
- **perf: bootstrap Caido concurrently with the scan start (#1143)** (1c499c5)
- **perf: take heavy imports off the startup path and pre-warm them in the background (#1141)** (1ce43d1)
- **fix(skills): avoid unquoted colon in api-security-testing description** (1b36343)
- **fix(report): raise RuntimeError on non-object run.json (fixes #1109) (#1116)** (e152c4c)
- **fix(tui): use single space after ordered-list marker (#1043)** (fe758af)
- **fix(tui): preserve cost when state is truncated (#1086)** (deb2057)
- **Fix LiteLLM cost model resolution** (8ca0c4a)

### UI
- **Show contextual CVSS details in CLI** — The CLI now displays additional security context for dependencies, including contextual CVSS vectors, advisory scores, and the reasoning behind CVSS assessments when generating vulnerability reports. (918442d)

### Backend
- **Link CLI wallet (#1222)** (3de9471)
- **Forward the workspace header through the wallet payment bridge (#1221)** (a071022)
- **pentest skill cloud cli (#1220)** (d26b1ab)
- **Make MCP connections survive transient transport failures (#1184)** (608ef4a)
- **csv injection hardening (#1203)** (3c767cd)
- **Isolate MCP connections per task and surface connection status in the UIs (#1181)** (717ffc8)
- **Reach MCP tools on demand instead of registering every one (#1175)** (cbb0f57)
- **Mirror the run's threat models into its state dir so resume keeps them** (8b655de)
- **Scope threat models to the current run instead of caching them on disk** (7d8d71b)
- **Treat literal 'null'/'none' strings as absent for optional tool args (#1164)** (187f41f)
- **Drop strict tool schemas on Claude routes** (d6f2218)
- **Require session token for run data** — Run data endpoints now require a valid session token for all access, including the initially launched run. Previously, the launched run was accessible without authentication; now all GET endpoints that expose scan output or metadata require the token-derived session capability, even when accessing from localhost. (6f88b7d)
- **Expose viewer host option** — The `strix view` command now exposes a `--host` option that lets users bind the viewer server to all IPv4 interfaces (using `0.0.0.0`) instead of just localhost, making it accessible from other machines. Documentation and tests were added to explain the feature and its security implications. (8d3693d)
- **Fix telemetry for resumed runs** — Improved handling of resume tokens so telemetry only counts new LLM usage and duration from the current process, not cumulative totals from previous runs. This ensures analytics accurately reflect work done in each session. (8ede419)
- **Contextual CVSS as a full 8-metric breakdown, computed like a normal finding** (e442db9)
- **reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning** (9c0d30a)
- **reporting: surface contextual CVSS in the markdown report; require reasoning only for surviving metrics** (55e6e66)
- **reporting: drop per-metric contextual CVSS reasoning, keep the summary** (99e2d5d)

### Docs
- **docs(skills): correct gRPC guidance, a .proto is not a spec target** (2cc8167)
- **docs(skills): document --workspace-file for supporting files** (d6a3ca7)
- **docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill** (9099710)
- **docs(skills): use current OWASP editions (Top 10:2025, API Top 10 2023)** (634cb98)

### Chore
- **chore: release v1.6.0** (8fdf6a5)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/usestrix/strix?utm_source=github-action)._