Claude Code
Security testing inside Claude Code, with the findings proven.
One slash command runs a structured application security assessment on your machine, using the Claude Code subscription you already have. Your repository stays local, and each finding says whether it was proven against your running application or only suspected.
npx myrqen@latest- Invocation /myrqen auto
- Account not required
- Model key none
First, the thing this page has to say
Claude Code already ships a security feature. /security-review has been there since August 2025, it is free with any Claude Code access, and it needs no setup. If you have not run it, run it before you install anything.
It reads your code and reasons about it. That is genuinely useful and it is a different job from this one:
/security-review | Myrqen | |
|---|---|---|
| What it does | Static analysis of code and diffs | Static pass, then each candidate exercised against the running application |
| Can it prove a finding? | No, it reasons about the code | Yes, for the classes a safe probe exists for. Under two identities and an admin. |
| Does it say when it is unsure? | Prose confidence | A verification state the CLI owns: verified, strong_evidence, needs_review. An agent cannot promote its own finding. |
| Boundary on what it may touch | Not needed, it touches nothing | Exact-origin grants, a prohibited-action list, quarantine for origins project text proposed |
| Languages | Whatever the model reads | JavaScript and TypeScript only |
| Artefacts | Terminal output, PR comments | HTML, JSON, Markdown, SARIF, written to your project |
| Published accuracy | None published | Precision 1.000, recall 0.441 against a gate of 0.90, and 0.294 blind |
| Works in Codex, OpenCode, Cursor | No | Yes, the same skill, thirteen agents |
| Cost | Free | Free for local scanning |
If reading the code is enough for you, use the free thing. Myrqen is for the point where you want an authorization bug shown to you by fetching another account's record, and a written record of everything the assessment could not settle.
Install it in Claude Code
One command. It detects Claude Code, shows you the plan, and writes nothing until you accept.
$ npx myrqen@latest
Detected coding agents
● Claude Code Confirmed 2.0.14
Ready to link Myrqen
Claude Code · this project
CREATE .claude/skills/myrqen/SKILL.md
MERGE CLAUDE.md existing content preservedThe slash command comes from the directory name, so the bundle installs as myrqen/ and is invoked as /myrqen. Your existing CLAUDE.md is preserved: Myrqen owns only the region between its own markers, and myrqen unlink returns the file byte for byte.
A project-scoped install writes into the repository, so a team all get the skill from the checkout. A global install writes into ~/.claude/skills/. myrqen link --scope project picks one.
Run an assessment
Start your application, then in Claude Code:
/myrqen autoauto resolves a depth from the size and shape of the project. low high xhigh ultra set it explicitly, depth changes breadth, reasoning passes and validation depth, and never changes what is authorized.
Claude Code then works the phases, and the CLI holds the contract:
- Discover, routes, identities, secrets, and dependencies, read from your source.
- Probe, candidates exercised against your running application. Never production.
- Settle, each candidate verified, refuted, or left explicitly unsettled.
- Fix, a remediation prompt and the test that should pass, handed straight back to Claude Code.
- Retest, run it again; the report says what closed and what came back.
The fix step is where running inside the agent pays off: Claude Code already has the file open, the context, and permission to edit. Copying a finding out of a dashboard into a chat window is the step this removes.
What a finding looks like
Real output from the deliberately vulnerable fixture in the repository.
MYR-004 high · verified
orders is read by identifier without checking who owns it
GET /api/orders/:id · src/server.js:95
Verified: signed in as user_a and requested /api/orders/102, a record
listed for user_b. The response was HTTP 200 with a body of 93 bytes.
Evidence · source · src/server.js:95
if (!user) return json(response, 401, { error: "sign in first" });
const id = Number(url.pathname.split("/").pop());
const order = orders.find((candidate) => candidate.id === id);
return json(response, 200, order);Severity and verification are independent, because "how bad if real" and "how sure it is real" are different questions. A candidate nobody exercised stays needs_review and says why, it is never promoted to make a report look better.
What it will not do
- Find everything. Recall is 0.441 against a gate of 0.90, and 0.294 on the one corpus nobody had tuned against. Every number, and the method.
- Read anything but JavaScript and TypeScript. Nothing else is parsed.
- Follow data across a module boundary. The static pass is intra-procedural by design; cross-module reasoning is Claude's part of the work, and the engine does not claim it.
- Anything destructive. At any depth. There is no flag.
- Touch a host you did not name. Authorizing
https://api.example.comauthorizes nothing else. - Tell you that you are secure. It reports what it established and states what it could not reach.
Common questions
- Does Myrqen work with Claude Code?
- Yes. It installs as a Claude Code Agent Skill and is invoked as /myrqen auto. myrqen link detects Claude Code, shows you the files it would write, .claude/skills/myrqen/ and a managed region in CLAUDE.md, asks, and then writes only those.
- How is this different from Claude Code's built-in /security-review?
- /security-review reads your code and reasons about it. Myrqen exercises each candidate against your running application under two identities and an admin, and records whether it was proven, supported by evidence, or left unsettled. /security-review is free and needs no setup, so run it first; use Myrqen when you want a finding demonstrated rather than described, and when you want an enforced boundary on what the agent may touch.
- Do I need a separate API key or subscription?
- No. Myrqen has no model of its own and never asks for a model provider credential. The reasoning comes from the Claude Code subscription you already pay for. There is nothing to buy to run a scan.
- Does Myrqen upload my repository?
- No. There is no code path that uploads your source tree. The only thing that can leave your machine is the finished report, and only if you answer yes to a question asked once per scan. Secret values never appear in a finding at all.
- Which languages does it support?
- JavaScript and TypeScript only. Python, Java, Ruby, Go, templates, and infrastructure definitions are not parsed at all. If your codebase is mostly not JavaScript or TypeScript, use a mature SAST product instead.
- Is Myrqen a SAST tool?
- Partly. It has a static pass of 36 rules, but a static candidate is not reported as a finding until an agent settles it against the running application, and if nobody does, it stays labelled needs_review. It is also not software composition analysis: dependency checks compare declared versions against a small offline table, with no lockfile resolution and no reachability.
- How accurate is it?
- Precision is 1.000 and no correct code has produced a finding on any corpus, so what it reports is worth acting on. Recall is 0.441 against our own gate of 0.90, and 0.294 on the one corpus nobody had tuned against. A report with no findings is not evidence that an application is secure. The full method and every number are published.
- Is Myrqen safe to run against my own app?
- Destructive actions are refused at every effort level and there is no opt-in flag: no mass deletion, no request flooding, no credential spraying, no persistence. Anything outside your own machine needs an exact-origin grant, and Myrqen never tests production, it exercises the application running locally.
- Is Myrqen free, and is it open source?
- Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account. It is not open source: the source is published under a source-available licence that grants reading and running, not redistribution.
Next
How accurate it is, and how that was measured · what leaves your machine · the exact contract the agent works inside · the same thing in Codex