Skip to main content
Myrqen is two things on your machine: the myrqen CLI, which owns session state, policy gates, finding intake, and reports; and a portable Agent Skill, which is the behavioural source of truth your coding agent reads. One command installs both.

Requirements

The published package is a single self-contained bundle plus the Agent Skill. It has no runtime dependencies.

Install the CLI

A bare myrqen runs link: it detects the coding agents on this machine, shows you exactly which files it would write, asks, and then writes only those.
Check what you got:

Release channels

0.1.0 is deprecated: it shipped without a README or a licence, included its sourcemap, and predates the entry-point adapters, so it is worse at detection as well.
Read the accuracy numbers before you trust a clean report. Myrqen’s precision is measured at 1.000 and its false-positive rate at 0.000 across every corpus — what it reports is worth reading. Its recall is 0.441 against a gate of 0.90, and the only measurement taken on a corpus nobody had tuned against scored 0.294. A report with no findings is not evidence that an application is secure. The full methodology, including what is excluded and why, is in Benchmark.

Build from source instead

You do not need this to use Myrqen. It is the path for reading the engine, or for working on it.
The repository is source-available, not open source: the licence grants reading and running it for your own work, and does not grant redistribution. See LICENSE.

Install the Agent Skill

myrqen link does this too — install is the same work without the account step. The bundle in the published package under skill/ is the single behavioural source of truth, and it is copied to whichever locations the agents on this machine actually read.

Which agents are supported

Thirteen integrations ship, each one an adapter that knows the exact file format that agent reads. myrqen link detects which are present and installs only those. Every path below is written under the repository for a project-scoped install and under your home directory for a global one. Each adapter names the vendor documentation it was verified against, with the date, in its own source file under apps/cli/src/integrations/adapters/. Notes that matter in practice:
  • Claude Code derives the slash command from the directory name, so the bundle installs as myrqen/ and is invoked as /myrqen auto. The frontmatter name is only the display label, and $ARGUMENTS carries the requested effort.
  • OpenCode also reads .claude/skills and .agents/skills, so one install can satisfy several agents. The installer deduplicates by destination path.
  • Codex has no slash-command mechanism, so the universal myrqen auto invocation is the documented path there.
  • A directory Myrqen manages carries a .myrqen-managed.json marker with the bundle version and a content digest, so a reinstall is a no-op when nothing changed. An existing directory Myrqen did not write is moved to myrqen.backup-<timestamp> first.
Find the source bundle at any time:
None of this is required. A missing integration does not mean the scanner is broken: the universal myrqen <effort> invocation works from any agent with shell access, and from a plain terminal.

Where local state lives

Two locations, and nothing outside them. Per machine — configuration and the device credential: config.json holds the API base URL, the linked account, update preferences, and the telemetry flag. The device token itself goes to the OS keystore — Keychain, Windows Credential Manager, or Secret Service — and falls back to a 0600 file only when no keystore is available. Per scanned repository — session and report state, under .myrqen/:
The repository’s own .gitignore already excludes .myrqen/local.json, .myrqen/reports/, .myrqen/sessions/, and .myrqen/current-session. Add the same lines to the project you are scanning. Override the config directory with MYRQEN_CONFIG_DIR — useful for keeping an experiment away from your real credential. See Environment variables.

Next

Link a device

Only needed for cloud reports and sharing. Scanning works unlinked.

Run your first assessment

What session start hands your agent, and what to do with it.