Runs
local
Precision
1.000
Recall
0.441
Blind
0.294
Gate
0.90

Myrqen found the bug.Then it proved it.

Local application security testing for JavaScript and TypeScript, inside the coding agent you already use. No separate model API key.

01npx myrqen@latest
02myrqen auto

Step 01 writes the skill into whichever agents are on the machine and prints what it wrote. Step 02 takes a depth, and auto picks one from the size and shape of the project. No account, no card, no model key.

Nothing leaves your machine. Recall is 0.441 against our own 0.90 gate, so a clean report is not evidence that an application is secure.

Claude Code · Codex · OpenCode · and ten more

assessmentvuln-shoplocal10.9s
  1. Discover
  2. Probe
  3. Settle
  4. Fix
  5. Retest
MYR-004verified

broken object level authorization

src/server.js:95GET /api/orders/102

settled by identity differential

Signed in as user_a and requested /api/orders/102, a record listed for user_b. The response was HTTP 200 with a body of 93 bytes.

src/server.js
  1. if (!user) return json(response, 401, { error: "sign in first" });
  2. const id = Number(url.pathname.split("/").pop());
  3. const order = orders.find((candidate) => candidate.id === id);
  4. if (!order) return json(response, 404, { error: "not found" });
  5. return json(response, 200, order);

4 destructive actions refused. 0 secrets in output.

14 findings9 verified, 5 unsettled5 shown

Two of these four are failures.

Scored against corpora committed to this repository, including one nobody had tuned the rules against. The method and the raw output are published.

1.000
precision, on every corpus
0.000
false positives on correct code
0.441
recall, against our own 0.90 gate
0.294
recall on the corpus nobody had tuned against

Precision that high means what it reports is worth acting on. Recall that low means it misses more than half of what a thorough human would find, so it belongs next to a review rather than instead of one. It parses JavaScript and TypeScript and nothing else, and it needs your application running locally to settle anything. Every corpus, the method, and the raw output.

One command, then five phases you can read.

There is no model key to buy and no runner to provision. The assessment is driven by the agent already sitting in your terminal, which is why it can read your project instead of guessing at it.

  1. Discover

    Routes, identities, secrets and dependencies, read from your source. The static pass parses your JavaScript and TypeScript and records where attacker-controlled data reaches a sink with nothing in between.

  2. Probe

    Your agent exercises each candidate against the application running on your machine, under two identities and an admin. Never production, and never an origin you did not name.

  3. Settle

    Each candidate is verified, refuted, or left explicitly unsettled. The CLI owns that state, not the agent, so a finding cannot promote itself.

  4. Fix

    Every finding carries a remediation prompt and the test that should pass afterwards, handed back to the agent that already has the file open.

  5. Retest

    Run it again. The report says what closed, what came back, and what was never reachable in the first place.

assessment5 phases
myrqen auto
  • reading fixtures/vuln-shop
  • 2 files parsed · 36 rules
  • 14 candidates recorded
  • 0 settled

Recorded run, fixtures/vuln-shop. Candidates, not findings.

myrqen action check --intent read_order_as_other_identity
  • target http://127.0.0.1:4010 · local, no grant needed
  • allowed: GET /api/orders/102 as user_a
  • refused: DELETE /api/orders (destructive)
  • refused: 2 origins named only by project text

4 destructive actions refused across the run. 0 allowed.

myrqen finding verify MYR-004
  • MYR-004 verified high
  • signed in as user_a, requested /api/orders/102,
  • a record listed for user_b. HTTP 200, 93 bytes.
  • 5 of 14 left needs_review, with the reason

9 of 14 reached verified. The other 5 say why they did not.

myrqen fix show MYR-004
  • make ownership part of the query, not a check after it
  • prompt copied to the agent
  • test: user_a requesting user_b's order gets 404

The fix is applied by your agent. Nothing edits your repository on its own.

myrqen auto
  • MYR-004 closed · 404 as user_a
  • report.html report.json report.md report.sarif.json
  • coverage: JS and TS only · flow followed within a function

Four formats, written to .myrqen/reports/ in your project. No expiry.

Run the free one first.

Claude Code ships /security-review and Codex ships Codex Security. Both are free with a subscription you may already hold, and both read your code well. If reading it is enough, use them.

This is for the point where you want the finding demonstrated instead of described, and a boundary on what the agent is allowed to touch while it does.

How a finding is settled

Reading the code

Reasoned about from the source. Useful, and not the same as proven.

Myrqen

Exercised against your running application under two identities and an admin.

How certainty is recorded

Reading the code

Confidence expressed in prose.

Myrqen

A verification state the CLI owns, so an agent cannot promote its own finding.

Boundary on what it may touch

Reading the code

Not needed. It touches nothing.

Myrqen

Exact-origin grants, a refusal list higher effort cannot relax, and quarantine for origins your project text proposed.

Published accuracy

Reading the code

None published.

Myrqen

Precision 1.000, recall 0.441 against a 0.90 gate, and 0.294 on the corpus nobody had tuned against.

Portability

Reading the code

Tied to the agent that ships it.

Myrqen

One skill bundle, thirteen agents, identical behaviour where slash commands do not exist.

Where it loses, and should: language breadth, dependency analysis, compliance reporting, CI gating, and price against a free feature built into the agent. The comparison in full.

Your repository is not the payload.

Scanning runs on your machine against your own project. Secrets, .env values, and raw traffic stay local. Cloud sync is a per-scan choice, and what syncs is the report you generated, never a copy of your source tree.

External APIs your project calls are only tested after you authorize that exact origin. Authorizing api.example.com never authorizes example.com or any sibling host.

Where the model comes from
Your agent. There is no Myrqen model key, and no prompt of yours reaches a model we operate.
What can be uploaded
A report, if you say so. Per scan, never by default, and never the source tree.
Synced report bodies
Encrypted at rest. Support cannot read one without a time-boxed grant written to an audit trail.
Destructive testing
Refused. The recorded run above refused 4 such actions and allowed none.
Data residency
EU. The application and the retention worker run in europe-west4. What is not independently verified about that is named on the security page.

It goes where your agent already is.

One bundle, installed into whichever agent you use. Thirteen integrations ship, each written against that vendor's own documented format.

The invocation does not change: /myrqen auto where slash commands exist, myrqen auto everywhere else.

  • Claude Codeslash command
  • Codex CLIshell
  • OpenCodeshell
  • Ten moreportable skill directory

Before you install anything.

Including the two answers that say this is the wrong tool. Longer versions: accuracy, what leaves your machine, pricing.

What is Myrqen?
Myrqen is a local-first application security assessment tool for JavaScript and TypeScript. It runs on your own machine, driven by the coding agent you already use, maps your project, exercises candidate vulnerabilities against your running application, and writes HTML, JSON, Markdown and SARIF reports you keep. There is no separate model API key and your repository is not uploaded.
Does Myrqen upload my source code?
No. There is no code path that uploads your source tree. The only thing that can leave your machine is the finished report, and only if you answer yes to a question asked once per scan. Secret values never appear in a finding, a report, or a progress event at all.
Do I need an OpenAI or Anthropic API key?
No. Myrqen has no model of its own and never asks for a model provider credential. The reasoning comes from the coding agent you already pay for. Claude Code, Codex, OpenCode, or one of ten others.
Which languages does Myrqen support?
JavaScript and TypeScript only, across Node, Bun, Deno and edge runtimes. Python, Java, Ruby, Go, template languages and infrastructure definitions are not parsed at all. A codebase that is mostly not JavaScript or TypeScript is the wrong fit.
How accurate is Myrqen?
Precision is 1.000 and the false-positive rate on deliberately correct code is 0.000, on every corpus including the one scored blind, so what it reports is worth acting on. Recall is 0.441 against our own gate of 0.90, and 0.294 on the corpus nobody had tuned against. A report with no findings is not evidence that an application is secure.
Is Myrqen safe to run? Does it scan production?
Destructive actions are refused at every effort level and there is no opt-in flag: no mass deletion, no request flooding, no credential spraying, no persistence. Myrqen never tests production: it exercises the application running on your machine. Anything outside that machine needs a grant naming the exact origin, and there is no wildcard form.
How much does Myrqen cost?
Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account and no card. Paid plans add cloud sync quota, retention and sharing, and cannot currently be bought because checkout is not configured on the hosted deployment.
Is Myrqen open source?
No. The source is published so the engine can be read and audited, under a source-available licence that grants reading and running it for your own work but not redistribution, forks, or running it as a service for other people. Please do not describe it as open source.

Find it before someone else does.

One command in the agent you already have open. Local scans, local reports and every export format are free and unlimited, and a vulnerability found on your machine is never withheld behind a paywall. What the paid plans add.

01npx myrqen@latest
02myrqen auto
  • Free and unlimited to scan, with no account and no card
  • No separate model API key. Your agent supplies the reasoning
  • Nothing uploaded unless you say so, once per scan
  • Source published and readable under a source-available licence. Read it