Claude Code

Security testing inside Claude Code, with the findings proven.

One slash command runs a structured application security assessment on your machine, using the Claude Code subscription you already have. Your repository stays local, and each finding says whether it was proven against your running application or only suspected.

npx myrqen@latest
  • Invocation /myrqen auto
  • Account not required
  • Model key none

First, the thing this page has to say

Claude Code already ships a security feature. /security-review has been there since August 2025, it is free with any Claude Code access, and it needs no setup. If you have not run it, run it before you install anything.

It reads your code and reasons about it. That is genuinely useful and it is a different job from this one:

/security-reviewMyrqen
What it doesStatic analysis of code and diffsStatic pass, then each candidate exercised against the running application
Can it prove a finding?No, it reasons about the codeYes, for the classes a safe probe exists for. Under two identities and an admin.
Does it say when it is unsure?Prose confidenceA verification state the CLI owns: verified, strong_evidence, needs_review. An agent cannot promote its own finding.
Boundary on what it may touchNot needed, it touches nothingExact-origin grants, a prohibited-action list, quarantine for origins project text proposed
LanguagesWhatever the model readsJavaScript and TypeScript only
ArtefactsTerminal output, PR commentsHTML, JSON, Markdown, SARIF, written to your project
Published accuracyNone publishedPrecision 1.000, recall 0.441 against a gate of 0.90, and 0.294 blind
Works in Codex, OpenCode, CursorNoYes, the same skill, thirteen agents
CostFreeFree for local scanning

If reading the code is enough for you, use the free thing. Myrqen is for the point where you want an authorization bug shown to you by fetching another account's record, and a written record of everything the assessment could not settle.

Install it in Claude Code

One command. It detects Claude Code, shows you the plan, and writes nothing until you accept.

$ npx myrqen@latest

Detected coding agents
  ● Claude Code       Confirmed  2.0.14

Ready to link Myrqen
Claude Code · this project
  CREATE  .claude/skills/myrqen/SKILL.md
  MERGE   CLAUDE.md            existing content preserved

The slash command comes from the directory name, so the bundle installs as myrqen/ and is invoked as /myrqen. Your existing CLAUDE.md is preserved: Myrqen owns only the region between its own markers, and myrqen unlink returns the file byte for byte.

A project-scoped install writes into the repository, so a team all get the skill from the checkout. A global install writes into ~/.claude/skills/. myrqen link --scope project picks one.

Run an assessment

Start your application, then in Claude Code:

/myrqen auto

auto resolves a depth from the size and shape of the project. low high xhigh ultra set it explicitly, depth changes breadth, reasoning passes and validation depth, and never changes what is authorized.

Claude Code then works the phases, and the CLI holds the contract:

  • Discover, routes, identities, secrets, and dependencies, read from your source.
  • Probe, candidates exercised against your running application. Never production.
  • Settle, each candidate verified, refuted, or left explicitly unsettled.
  • Fix, a remediation prompt and the test that should pass, handed straight back to Claude Code.
  • Retest, run it again; the report says what closed and what came back.

The fix step is where running inside the agent pays off: Claude Code already has the file open, the context, and permission to edit. Copying a finding out of a dashboard into a chat window is the step this removes.

What a finding looks like

Real output from the deliberately vulnerable fixture in the repository.

MYR-004   high · verified
orders is read by identifier without checking who owns it
GET /api/orders/:id  ·  src/server.js:95

  Verified: signed in as user_a and requested /api/orders/102, a record
  listed for user_b. The response was HTTP 200 with a body of 93 bytes.

  Evidence · source · src/server.js:95
      if (!user) return json(response, 401, { error: "sign in first" });
      const id = Number(url.pathname.split("/").pop());
      const order = orders.find((candidate) => candidate.id === id);
      return json(response, 200, order);

Severity and verification are independent, because "how bad if real" and "how sure it is real" are different questions. A candidate nobody exercised stays needs_review and says why, it is never promoted to make a report look better.

What it will not do

  • Find everything. Recall is 0.441 against a gate of 0.90, and 0.294 on the one corpus nobody had tuned against. Every number, and the method.
  • Read anything but JavaScript and TypeScript. Nothing else is parsed.
  • Follow data across a module boundary. The static pass is intra-procedural by design; cross-module reasoning is Claude's part of the work, and the engine does not claim it.
  • Anything destructive. At any depth. There is no flag.
  • Touch a host you did not name. Authorizing https://api.example.com authorizes nothing else.
  • Tell you that you are secure. It reports what it established and states what it could not reach.

Common questions

Does Myrqen work with Claude Code?
Yes. It installs as a Claude Code Agent Skill and is invoked as /myrqen auto. myrqen link detects Claude Code, shows you the files it would write, .claude/skills/myrqen/ and a managed region in CLAUDE.md, asks, and then writes only those.
How is this different from Claude Code's built-in /security-review?
/security-review reads your code and reasons about it. Myrqen exercises each candidate against your running application under two identities and an admin, and records whether it was proven, supported by evidence, or left unsettled. /security-review is free and needs no setup, so run it first; use Myrqen when you want a finding demonstrated rather than described, and when you want an enforced boundary on what the agent may touch.
Do I need a separate API key or subscription?
No. Myrqen has no model of its own and never asks for a model provider credential. The reasoning comes from the Claude Code subscription you already pay for. There is nothing to buy to run a scan.
Does Myrqen upload my repository?
No. There is no code path that uploads your source tree. The only thing that can leave your machine is the finished report, and only if you answer yes to a question asked once per scan. Secret values never appear in a finding at all.
Which languages does it support?
JavaScript and TypeScript only. Python, Java, Ruby, Go, templates, and infrastructure definitions are not parsed at all. If your codebase is mostly not JavaScript or TypeScript, use a mature SAST product instead.
Is Myrqen a SAST tool?
Partly. It has a static pass of 36 rules, but a static candidate is not reported as a finding until an agent settles it against the running application, and if nobody does, it stays labelled needs_review. It is also not software composition analysis: dependency checks compare declared versions against a small offline table, with no lockfile resolution and no reachability.
How accurate is it?
Precision is 1.000 and no correct code has produced a finding on any corpus, so what it reports is worth acting on. Recall is 0.441 against our own gate of 0.90, and 0.294 on the one corpus nobody had tuned against. A report with no findings is not evidence that an application is secure. The full method and every number are published.
Is Myrqen safe to run against my own app?
Destructive actions are refused at every effort level and there is no opt-in flag: no mass deletion, no request flooding, no credential spraying, no persistence. Anything outside your own machine needs an exact-origin grant, and Myrqen never tests production, it exercises the application running locally.
Is Myrqen free, and is it open source?
Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account. It is not open source: the source is published under a source-available licence that grants reading and running, not redistribution.

Next

How accurate it is, and how that was measured · what leaves your machine · the exact contract the agent works inside · the same thing in Codex