Myrqen is only for projects and targets you own or are authorized to test. Run it
against something of yours. Pointing it at somebody else’s application is not what it is
for, and the authorization gate refuses any origin
you have not granted by name.
1. Install
myrqen link: it detects the coding agents installed on this machine, prints
exactly which files it would write, asks, and then writes only those. Existing
instructions are preserved, a second run changes nothing, and myrqen unlink removes
only Myrqen’s own content.
You need Node.js 20.12 or newer and one of thirteen supported coding
agents — or no agent at all,
if you are content to drive the CLI yourself.
Confirm what this machine can assess:
doctor reports capability rather than alarm. “No account is connected” is info, not a
problem: scanning is local and complete without one.
2. Start the application you want assessed
The scan is far more useful against something that is running, because that is what turns a static candidate into a verified finding.needs_review and the report
says so rather than implying they were proven.
3. Run the assessment
- Claude Code
- Any other agent
- No agent
auto inspects the project’s size and surface and resolves a concrete
effort profile, then prints the session context: the local
report id, the resolved effort and why, the local targets it found, the external origins
it will not touch without an explicit grant, and the artifact paths it will write.
--sync no keeps everything local. Without it, and on a linked device, Myrqen asks once
whether to sync this scan — see Cloud sync.
Read the context back at any time:
4. Read the report
.myrqen/reports/, .myrqen/sessions/, .myrqen/current-session, and
.myrqen/local.json to the project’s .gitignore.
Reproduce a deterministic run
The steps above involve a language model, so no two runs are identical. The repository ships a fixture with machine-readable ground truth and a scripted stand-in agent, which together produce the same result every time — this is what the benchmark gate and every published number are computed from. It needs a source checkout, because the fixture and the harness are not part of the npm package:fixtures/vuln-shop is a Myrqen-owned application with deliberate defects, described in
fixtures/vuln-shop/ground-truth.json. It binds to loopback only and keeps everything in
memory. Every credential in it is a fake canary used to prove that redaction works, and
none of them reaches any artifact:Next steps
Run it with your own agent
The exact contract the agent works inside, phase by phase.
Understand the safety model
Read this before you point Myrqen at anything that is not on your own machine.
Fix a finding and retest
The remediation prompt, the applied change, and the honest verification record.
Connect an account
Optional. Adds live progress, retention, and one share URL that renders differently
per recipient.