Codex CLI · OpenCode
Security testing from Codex or OpenCode, without uploading your repository.
One command installs a portable Agent Skill into whichever agent you use. The assessment runs on your machine, proves what it can against your running application, and writes reports you keep. No slash command needed, and no second model key.
npx myrqen@latest- Invocation myrqen auto
- Account not required
- Uploaded nothing
Codex has its own security product. Read this first.
Codex Security launched in March 2026 and is free for ChatGPT Pro and Enterprise. It ingests a repository's full commit log, reasons about how the code changed over time, and can open remediation pull requests. Finding a vulnerability that was introduced two years ago and never noticed is something Myrqen does not attempt.
The trades are real in both directions:
| Codex Security | Myrqen | |
|---|---|---|
| Where it runs | OpenAI's service. Your repository is ingested. | Your machine. Nothing is uploaded but the report, and only if you ask. |
| What it reads | The full commit history | The working tree in front of it |
| How a finding is settled | Reasoning, then an automated fix pull request | Exercised against your running application under two identities and an admin, with the outcome recorded as a verification state |
| Maturity | Research preview | Released, with published accuracy including the bad number |
| Languages | Broad | JavaScript and TypeScript only |
| Portable to another agent | No | Yes, thirteen agents, one skill bundle |
They are not substitutes. If your constraint is the repository must not leave the machine, or you want a finding demonstrated rather than argued, that is what this is for.
Install
$ npx myrqen@latest
Detected coding agents
● Codex CLI Confirmed
● OpenCode Confirmed
Ready to link Myrqen
Codex CLI · this project
CREATE .codex/skills/myrqen/SKILL.md
OpenCode · this project
CREATE .config/opencode/skills/myrqen/SKILL.mdNothing is written before that plan is printed and accepted. --dry-run prints it and stops, --agent codex narrows it to one agent, and myrqen unlink removes only Myrqen's own files.
Neither Codex nor OpenCode has a slash-command mechanism, so there is no /myrqen here and none is faked. The universal invocation is the documented path, and it behaves identically to the slash command elsewhere.
Run an assessment
Start your application, then ask the agent to run:
myrqen autoThe skill bundle is what tells the agent how to work the phases; the CLI owns the contract. The agent submits candidates, and the CLI, not the agent, assigns identity, deduplicates, redacts, caps severity by policy, and decides what verification state a finding is allowed to carry. An agent cannot promote its own finding to verified.
Depth is a policy profile, and it never changes what is authorized:
| Depth | What changes |
|---|---|
auto | Resolves from the size and shape of the project. The right answer for almost everybody. |
low | A fast pass over the routes and the obvious surface. |
high | The default depth for a real review. |
xhigh | Adds identity differentials and longer chains. |
ultra | Everything, and it will take its time. |
Switching agents does not mean switching tools
Thirteen integrations ship, each written against that vendor's own documented configuration format: Claude Code, Codex CLI, OpenCode, Cursor, Windsurf, GitHub Copilot, Gemini CLI, Cline, Roo Code, Continue, Kiro, Aider, and a shared AGENTS.md fallback.
That matters more than it sounds. A security feature built into one agent is a reason not to change agent, and this market changes every few months. The skill bundle is the behavioural source of truth and it is the same file everywhere. Every agent, and the exact file written for each.
What it will not do
- Find everything. Recall is 0.441 against a gate of 0.90, and 0.294 blind. The method and every number.
- Read anything but JavaScript and TypeScript.
- Follow data across a module boundary. That is handed to the agent by design.
- Anything destructive, at any depth. There is no opt-in flag.
- Touch a host you did not name. No wildcard grants exist.
- Scan production. It exercises the application running on your machine.
Common questions
- Does Myrqen work with Codex?
- Yes. myrqen link installs the skill bundle into .codex/skills/myrqen/, and the assessment is driven with myrqen auto from Codex's shell. Codex has no slash-command mechanism, so the CLI invocation is the documented path there.
- Does Myrqen work with OpenCode?
- Yes, the same way: the bundle installs into .config/opencode/skills/myrqen/ and the assessment runs as myrqen auto. OpenCode also reads .claude/skills and .agents/skills, so one install can satisfy several agents, the installer deduplicates by destination path.
- How is this different from Codex Security?
- Codex Security ingests your repository and its full commit history into OpenAI's service and reasons about how the code changed over time, which is a genuinely different and useful angle. Myrqen runs entirely on your machine, uploads nothing, and exercises candidates against your running application. OpenAI's own material describes Codex Security as a research preview that is slower, compute-intensive, and not a replacement for static analysis where high recall is required.
- Do I need a separate API key?
- No. Myrqen has no model of its own and never asks for a model provider credential. The reasoning comes from the agent subscription you already pay for.
- Which languages does it support?
- JavaScript and TypeScript only, including Node, Bun, Deno and edge runtimes. Python, Java, Ruby, Go, templates and infrastructure definitions are not parsed at all.
- Can I run it without any agent at all?
- Yes. myrqen auto from a plain terminal runs the static pass, writes all four report formats, and prints the coverage notes. Without an agent nobody exercises the candidates against the running application, so every one stays needs_review, which the report says rather than implying they were proven.
- How accurate is it?
- Precision is 1.000 and no correct code has produced a finding on any corpus. Recall is 0.441 against our own gate of 0.90, and 0.294 on the one corpus nobody had tuned against. A report with no findings is not evidence that an application is secure.
- Is Myrqen free, and is it open source?
- Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account. It is not open source: the source is published under a source-available licence that grants reading and running, not redistribution.
Next
Measured accuracy, and how it was measured · what leaves your machine · the agent contract, phase by phase · the slash-command version, in Claude Code