- Rename max_chars → threshold_chars and add separate truncate_to_chars
parameter so the threshold and truncation target can differ by design,
replacing the hardcoded 1000. Callers can now shrink blocks aggressively
without re-processing blocks that are already acceptable.
- Add 2s sleep before the truncation-path `continue` to match the bare-retry
pacing. If Bedrock is throttling after the original 400, immediately hitting
it again risks a second rejection before the truncated payload is evaluated.
Remove one-shot bad_request_truncated guard so truncation retries on each
400 until nothing remains to truncate. Also scan all messages per pass
instead of stopping at the first hit.
Addresses review feedback from Greptile on #460.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
When tool results (e.g. large config files, CIS benchmark YAML) accumulate
in conversation history, the serialized payload can exceed the provider's
request size limit, causing a persistent HTTP 400. Previously this was not
retried, failing the scan immediately.
Now handles BadRequestError in two stages:
1. Bare retry after 2s (transient 400s from provider hiccups)
2. If STRIX_TRUNCATE_ON_OVERSIZE=true, truncates the largest tool_result
XML blocks to 1000 chars with a "requires manual review" notice, then
retries. This is opt-in to avoid lossy recovery for users who don't
want it.
Observed in practice on repos with 50KB+ CIS defaults YAML and 94KB
tfvars.json files hitting Bedrock payload limits at ~6M tokens.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Models occasionally output text-only narration ("Planning the
assessment...") without a tool call, which halts the interactive agent
loop since the system interprets no-tool-call as "waiting for user
input." Rewrite both interactive and autonomous prompt sections to make
the tool-call requirement absolute with explicit warnings about the
system halt consequence.
- Change default model from gpt-5 to gpt-5.4 across docs, tests, and examples
- Remove Strix Router references from docs, quickstart, overview, and README
- Delete models.mdx (Strix Router page) and its nav entry
- Simplify install script to suggest openai/ prefix directly
- Keep strix/ model routing support intact in code
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Re-architects the agent loop to support interactive (chat-like) mode
where text-only responses pause execution and wait for user input,
while tool-call responses continue looping autonomously.
- Add `interactive` flag to LLMConfig (default False, no regression)
- Add configurable `waiting_timeout` to AgentState (0 = disabled)
- _process_iteration returns None for text-only → agent_loop pauses
- Conditional system prompt: interactive allows natural text responses
- Skip <meta>Continue the task.</meta> injection in interactive mode
- Sub-agents inherit interactive from parent (300s auto-resume timeout)
- Root interactive agents wait indefinitely for user input (timeout=0)
- TUI sets interactive=True; CLI unchanged (non_interactive=True)
The perplexity API key check in strix/tools/__init__.py used
Config.get() which only checks os.environ. At import time, the
config file (~/.strix/cli-config.json) hasn't been applied to
env vars yet, so the check always returned False.
Replace with _has_perplexity_api() that checks os.environ first
(fast path for SaaS/env var), then falls back to Config.load()
which reads the config file directly.
Users can now access the Caido web UI from their browser to inspect traffic,
replay requests, and perform manual testing alongside the automated scan.
- Map Caido port (48080) to a random host port in DockerRuntime
- Add caido_port to SandboxInfo and track across container lifecycle
- Display Caido URL in TUI sidebar stats panel with selectable text
- Bind Caido to 0.0.0.0 in entrypoint (requires image rebuild)
- Bump sandbox image to 0.1.12
- Restore discord link in exit screen
The badge image URL used invite code which is expired,
causing the badge to render 'Invalid invite' instead of the server info.
Updated to use the vanity URL which resolves correctly.
Fixes#313