Discover
Routes, identities, secrets and dependencies, read from your source. The static pass parses your JavaScript and TypeScript and records where attacker-controlled data reaches a sink with nothing in between.
Probe
Your agent exercises each candidate against the application running on your machine, under two identities and an admin. Never production, and never an origin you did not name.
Settle
Each candidate is verified, refuted, or left explicitly unsettled. The CLI owns that state, not the agent, so a finding cannot promote itself.
Fix
Every finding carries a remediation prompt and the test that should pass afterwards, handed back to the agent that already has the file open.
Retest
Run it again. The report says what closed, what came back, and what was never reachable in the first place.
myrqen auto- reading fixtures/vuln-shop
- 2 files parsed · 36 rules
- 14 candidates recorded
- 0 settled
Recorded run, fixtures/vuln-shop. Candidates, not findings.
myrqen action check --intent read_order_as_other_identity- target http://127.0.0.1:4010 · local, no grant needed
- allowed: GET /api/orders/102 as user_a
- refused: DELETE /api/orders (destructive)
- refused: 2 origins named only by project text
4 destructive actions refused across the run. 0 allowed.
myrqen finding verify MYR-004- MYR-004 verified high
- signed in as user_a, requested /api/orders/102,
- a record listed for user_b. HTTP 200, 93 bytes.
- 5 of 14 left needs_review, with the reason
9 of 14 reached verified. The other 5 say why they did not.
myrqen fix show MYR-004- make ownership part of the query, not a check after it
- prompt copied to the agent
- test: user_a requesting user_b's order gets 404
The fix is applied by your agent. Nothing edits your repository on its own.
myrqen auto- MYR-004 closed · 404 as user_a
- report.html report.json report.md report.sarif.json
- coverage: JS and TS only · flow followed within a function
Four formats, written to .myrqen/reports/ in your project. No expiry.