Codex CLI · OpenCode

Security testing from Codex or OpenCode, without uploading your repository.

One command installs a portable Agent Skill into whichever agent you use. The assessment runs on your machine, proves what it can against your running application, and writes reports you keep. No slash command needed, and no second model key.

npx myrqen@latest
  • Invocation myrqen auto
  • Account not required
  • Uploaded nothing

Codex has its own security product. Read this first.

Codex Security launched in March 2026 and is free for ChatGPT Pro and Enterprise. It ingests a repository's full commit log, reasons about how the code changed over time, and can open remediation pull requests. Finding a vulnerability that was introduced two years ago and never noticed is something Myrqen does not attempt.

The trades are real in both directions:

Codex SecurityMyrqen
Where it runsOpenAI's service. Your repository is ingested.Your machine. Nothing is uploaded but the report, and only if you ask.
What it readsThe full commit historyThe working tree in front of it
How a finding is settledReasoning, then an automated fix pull requestExercised against your running application under two identities and an admin, with the outcome recorded as a verification state
MaturityResearch previewReleased, with published accuracy including the bad number
LanguagesBroadJavaScript and TypeScript only
Portable to another agentNoYes, thirteen agents, one skill bundle

They are not substitutes. If your constraint is the repository must not leave the machine, or you want a finding demonstrated rather than argued, that is what this is for.

Install

$ npx myrqen@latest

Detected coding agents
  ● Codex CLI         Confirmed
  ● OpenCode          Confirmed

Ready to link Myrqen
Codex CLI · this project
  CREATE  .codex/skills/myrqen/SKILL.md
OpenCode · this project
  CREATE  .config/opencode/skills/myrqen/SKILL.md

Nothing is written before that plan is printed and accepted. --dry-run prints it and stops, --agent codex narrows it to one agent, and myrqen unlink removes only Myrqen's own files.

Neither Codex nor OpenCode has a slash-command mechanism, so there is no /myrqen here and none is faked. The universal invocation is the documented path, and it behaves identically to the slash command elsewhere.

Run an assessment

Start your application, then ask the agent to run:

myrqen auto

The skill bundle is what tells the agent how to work the phases; the CLI owns the contract. The agent submits candidates, and the CLI, not the agent, assigns identity, deduplicates, redacts, caps severity by policy, and decides what verification state a finding is allowed to carry. An agent cannot promote its own finding to verified.

Depth is a policy profile, and it never changes what is authorized:

DepthWhat changes
autoResolves from the size and shape of the project. The right answer for almost everybody.
lowA fast pass over the routes and the obvious surface.
highThe default depth for a real review.
xhighAdds identity differentials and longer chains.
ultraEverything, and it will take its time.

Switching agents does not mean switching tools

Thirteen integrations ship, each written against that vendor's own documented configuration format: Claude Code, Codex CLI, OpenCode, Cursor, Windsurf, GitHub Copilot, Gemini CLI, Cline, Roo Code, Continue, Kiro, Aider, and a shared AGENTS.md fallback.

That matters more than it sounds. A security feature built into one agent is a reason not to change agent, and this market changes every few months. The skill bundle is the behavioural source of truth and it is the same file everywhere. Every agent, and the exact file written for each.

What it will not do

  • Find everything. Recall is 0.441 against a gate of 0.90, and 0.294 blind. The method and every number.
  • Read anything but JavaScript and TypeScript.
  • Follow data across a module boundary. That is handed to the agent by design.
  • Anything destructive, at any depth. There is no opt-in flag.
  • Touch a host you did not name. No wildcard grants exist.
  • Scan production. It exercises the application running on your machine.

Common questions

Does Myrqen work with Codex?
Yes. myrqen link installs the skill bundle into .codex/skills/myrqen/, and the assessment is driven with myrqen auto from Codex's shell. Codex has no slash-command mechanism, so the CLI invocation is the documented path there.
Does Myrqen work with OpenCode?
Yes, the same way: the bundle installs into .config/opencode/skills/myrqen/ and the assessment runs as myrqen auto. OpenCode also reads .claude/skills and .agents/skills, so one install can satisfy several agents, the installer deduplicates by destination path.
How is this different from Codex Security?
Codex Security ingests your repository and its full commit history into OpenAI's service and reasons about how the code changed over time, which is a genuinely different and useful angle. Myrqen runs entirely on your machine, uploads nothing, and exercises candidates against your running application. OpenAI's own material describes Codex Security as a research preview that is slower, compute-intensive, and not a replacement for static analysis where high recall is required.
Do I need a separate API key?
No. Myrqen has no model of its own and never asks for a model provider credential. The reasoning comes from the agent subscription you already pay for.
Which languages does it support?
JavaScript and TypeScript only, including Node, Bun, Deno and edge runtimes. Python, Java, Ruby, Go, templates and infrastructure definitions are not parsed at all.
Can I run it without any agent at all?
Yes. myrqen auto from a plain terminal runs the static pass, writes all four report formats, and prints the coverage notes. Without an agent nobody exercises the candidates against the running application, so every one stays needs_review, which the report says rather than implying they were proven.
How accurate is it?
Precision is 1.000 and no correct code has produced a finding on any corpus. Recall is 0.441 against our own gate of 0.90, and 0.294 on the one corpus nobody had tuned against. A report with no findings is not evidence that an application is secure.
Is Myrqen free, and is it open source?
Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account. It is not open source: the source is published under a source-available licence that grants reading and running, not redistribution.

Next

Measured accuracy, and how it was measured · what leaves your machine · the agent contract, phase by phase · the slash-command version, in Claude Code