JavaScript · TypeScript

A security scanner that tells you what it did not check.

36 rules over your JavaScript and TypeScript source, entry points recognised across nineteen framework and runtime shapes, and every candidate exercised against your running application before it is called a finding. It runs locally, and the coverage it did not reach is printed in the report rather than left for you to assume.

npx myrqen@latest
  • Precision 1.000
  • Recall 0.441 against a 0.90 gate
  • Uploaded nothing

What makes this different from the other twelve

Most scanners in this category match patterns and hand you a list. Three things here are not that:

  • A candidate is not a finding until something exercised it. The static pass produces candidates; your coding agent settles each one against the running application under two identities and an admin. The result is recorded as verified, strong_evidence, or needs_review, and severity is a separate axis, because "how bad if real" and "how sure it is real" are different questions.
  • The report states its own coverage. Every report ends with what was not assessed, in the engine's own words. Silence from a scanner is not a clean bill of health, and this one says so in writing.
  • The miss rate is published. Not the flattering number, the one from the corpus nobody had tuned against. Method, corpora, per-class results, raw output.

What it can see

A rule is only useful if the engine can find the entry point it applies to. Without an adapter for a framework's route shape, there is no handler to follow anything into, which is why the previous release detected far less. These are the shapes recognised today.

SurfaceRecognised
NodeExpress, Fastify, Koa-style handlers, raw http servers, tRPC procedures, GraphQL resolvers
Full-stack frameworksNext.js route handlers and server actions, Nest controllers, Nitro, SvelteKit, Astro, Remix, TanStack/Solid
Alternative runtimesBun.serve, Deno and Deno Fresh, Cloudflare Workers
ServerlessHandler-shaped exports across the common providers
Other surfacesEditor-extension commands and message handlers, desktop CLI entry points, realtime and WebSocket handlers
Data access recognised as a sinkRaw SQL, prepared statements, Drizzle and Kysely fluent builders, Prisma, key-value and document stores

Not recognised: anything that is not JavaScript or TypeScript, template languages, configuration files, and infrastructure definitions. Data flow is followed within a function, a value that becomes attacker-controlled in one module and reaches a sink in another is not connected by the engine, and is handed to your agent instead.

What it found, and what it missed

Per class, on the held-out corpus of 68 cases: 15 of 34 vulnerable cases detected. The misses are in the table because they are the useful half.

ClassExpectedDetected
missing authentication20
broken function level authorization20
business logic price manipulation10
timing unsafe comparison10
secret exposed to client bundle10
stored cross site scripting10
nosql injection10
mass assignment10
broken object level authorization51
race condition double spend31
sql injection53
path traversal32
server side request forgery44
command injection22
prototype pollution11
insecure cors configuration11

The classes at zero are ones the engine has no rule for yet, not ones it looked at and got wrong. That is fixable work, and until it is done it is a class Myrqen will not find in your code either. The development corpus exercises 38 classes in total and reports 1.000, which is what a regression gate looks like and says nothing about unseen code.

How you use it

npx myrqen@latest        # detects your coding agents, sets them up
npm run dev                     # start the application you are assessing

/myrqen auto                    # in Claude Code
myrqen auto                    # from Codex, OpenCode, or a plain terminal

Reports land in .myrqen/reports/ in the project you scanned, in four formats: self-contained HTML that opens with the network off, JSON, Markdown, and SARIF for whatever consumes it. They have no expiry and nothing on our side can remove them.

Without a coding agent the static pass still runs and still writes all four reports, every candidate simply stays needs_review, because nobody exercised it. The Claude Code workflow · Codex and OpenCode

When to use something else

Stated here rather than discovered later:

  • A codebase that is mostly not JavaScript or TypeScript. Nothing else is parsed. Use a mature SAST product.
  • Dependency, licence, or supply-chain inventory. This is not composition analysis.
  • A CI gate that must catch everything. At 0.441 recall it would pass code it should not, and a passing gate reads as a guarantee.
  • A compliance artefact or an audit report. No third party has audited Myrqen.
  • Scanning a deployed production system, or one you do not own. Myrqen exercises the application on your machine and refuses destructive actions, by design.

Common questions

What is Myrqen?
A local-first application security assessment tool for JavaScript and TypeScript. It runs on your machine, driven by the coding agent you already use, maps the project, exercises candidate vulnerabilities against your running application, and writes HTML, JSON, Markdown and SARIF reports you keep. There is no separate model API key and your repository is not uploaded.
Is Myrqen a SAST tool?
Partly. There is a static pass of 36 rules over your JavaScript and TypeScript source, but a static candidate is not reported as a proven finding until an agent settles it against the running application. Findings that nobody exercised are labelled needs_review rather than presented as certainties.
Does it do software composition analysis?
No. Dependency checks compare declared versions against a small offline advisory table, with no lockfile resolution and no reachability analysis. If you need dependency and licence inventory, use a dedicated composition analysis product.
Which JavaScript frameworks does it understand?
Express, Fastify, Next.js, Nest, Nitro, SvelteKit, Astro, Remix, TanStack and Solid, tRPC, GraphQL resolvers, Bun.serve, Deno and Deno Fresh, Cloudflare Workers, serverless handlers, editor extensions and desktop CLI entry points. Data access is recognised through raw SQL, prepared statements, Drizzle, Kysely, Prisma and key-value stores.
Which vulnerability classes does it look for?
SQL and NoSQL injection, command and argument injection, code injection, path traversal and zip slip, server-side request forgery, broken object-level and function-level authorization, missing authentication, mass assignment, insecure CORS, open redirect, reflected and stored cross-site scripting, prototype pollution, weak password hashing, timing-unsafe comparison, weak session identifiers, hardcoded secrets, secrets exposed to a client bundle, unrestricted file upload, insecure cookie configuration, verbose error responses, debug endpoint exposure, business-logic price manipulation, and double-spend races. 38 classes are exercised by the development corpus.
How accurate is it?
Precision is 1.000 and the false-positive rate on deliberately correct code is 0.000, on every corpus including the one scored blind. Recall is 0.441 against our own gate of 0.90, and 0.294 on the corpus nobody had tuned against. A report with no findings is not evidence that an application is secure.
Does it upload my source code?
No. There is no code path that uploads your source tree. The only thing that can leave your machine is the finished report, and only if you answer yes to a question asked once per scan. Secret values never appear in a finding, a report, or a progress event at all.
Does it scan Python, Java, Ruby or Go?
No. Those languages are not parsed at all, and neither are templates or infrastructure definitions. A codebase that is mostly not JavaScript or TypeScript is the wrong fit and you should use a mature SAST product instead.
How much does it cost?
Local scanning, local reports in all four formats, and every finding at every severity are free and unlimited, with no account and no card. Paid plans add cloud sync quota, retention and sharing, and cannot currently be bought, because checkout is not configured.
Is Myrqen open source?
No. The source is published so the engine can be read and audited, under a licence that grants reading and running it for your own work but not redistribution, forks, or hosting it for other people. Please do not describe it as open source.

Next

Measured accuracy, and how it was measured · what leaves your machine · documentation · npm