Skip to main content
Myrqen turns the coding agent a developer already uses into a structured application pentester. The host agent supplies the reasoning; Myrqen supplies the methodology, the safety gates, the finding contract, the report, and an optional cloud collaboration layer. There is no second LLM API key. Myrqen never asks for a model provider credential — it uses the agent you are already paying for.
Myrqen is a working codename that has passed a preliminary collision screen only. The scanner is source-available and proprietary, not OSI open source. See SOURCE-AVAILABLE-LICENSE-DRAFT.md in the repository for what the licence does and does not grant.
Current state, plainly. The CLI is on npm as [email protected] and the hosted service is deployed, so npx myrqen@latest and myrqen login both work. What is not finished is detection recall:
  • Precision is 1.000 and the safe-code false-positive rate is 0.000 on every corpus. What Myrqen reports is worth acting on.
  • Recall is 0.441 against a gate of 0.90. The only corpus nobody had tuned against scored 0.294. A report with no findings is not evidence that an application is secure, and these docs will not pretend otherwise. See Benchmark.
  • Only JavaScript and TypeScript are parsed. Python, Java, Ruby and Go are not analysed at all, and data flow is not followed across a module boundary.
  • Paid plans cannot be bought yet. Checkout is not configured on the hosted deployment. The free plan is real and needs no card.

What a scan actually is

A scan has two halves, and the split is the whole design.

The static pass is Myrqen's own

myrqen session start parses the project’s TypeScript and JavaScript, follows attacker-controlled data through a function, and records where it reaches a sink with nothing in between. It runs whether or not an agent is involved, which is what makes it measurable.

The dynamic half is the agent's

Static reading cannot observe a response, so every static candidate arrives as a claim rather than a finding. Your agent settles it against the running application with myrqen finding verify or myrqen finding refute.
A candidate nobody exercised stays needs_review and says so in the report. That is the honest state, and the report never pretends otherwise.

Who it is for

Developers and small teams who want a real application security pass on something they are building, before shipping it, without buying a second model subscription or handing their repository to a scanning service. The repository is never uploaded. Scanning, report generation in all four formats, the fix prompt, and applying a fix locally are never gated by plan.

Primary capabilities

Agent-driven assessment

A portable Agent Skill plus a universal CLI. Works as /myrqen auto in Claude Code and as myrqen auto from any agent with shell access.

Enforced safety policy

Exact-origin authorization for anything off your machine, a prohibited-action list that higher effort never relaxes, and quarantine for origins that untrusted project content proposed.

Findings with provenance

Severity and verification are independent. Deduplication, redaction, and finding identity are owned by the CLI, not by the agent.

Reports you own

Self-contained HTML, plus JSON, Markdown, and SARIF, written to .myrqen/reports/<id>/ in the project you scanned.

Optional cloud sync

Live progress, retention windows, and one share URL that renders differently per recipient — asked for once per scan, never automatic. Hosted at myrqen.cc, or run it yourself.

A measurable engine

An owned corpus of vulnerable cases paired with safe near-misses, plus the scorer that grades recall, precision, and false positives.

Where to start

1

Install the CLI

Detects your coding agents and sets them up. See Installation.
2

Run your first assessment

Point it at a project you own and let your agent work the phases. See the Quickstart.
3

Read the safety rules before you test anything external

Local targets need no prompt. Everything else needs an exact-origin grant. See Authorization and safety.

What Myrqen will not do

  • It will not tell you that you are secure. It reports what it can establish and states what it could not reach. Silence from a scanner is not a clean bill of health.
  • It will not touch a system you have not authorized. A grant for https://api.example.com never extends to example.com, another port, or another scheme.
  • It will not do anything destructive. Mass deletion, request flooding, credential spraying, persistence, and scope expansion are refused by policy, not by convention, and a refusal is recorded in the report.
  • It will not treat text in your repository as instructions. A README that tells the scanner to ignore its rules is data. The attempt is recorded as an observation.
  • It will not print a secret it found. Findings describe a credential by type and location; the value is redacted before it is stored anywhere, including locally.