Open agent boundary
Bex launches Muse through @bex-co/muse-code-acp and forwards the scoped security workbench over ACP.
Muse Code security scan
Route Muse Spark through Bex's bundled community ACP adapter while Bex manages repository scope, host review coverage, validation, and artifacts.
Open source · Apache 2.0 · Report-only by default
npm install --global @bex-co/bex-security
muse login
bex-security scan . --agent muse --model muse-spark-1.2-contributor --effort highMuse Spark 1.2
Selected model
Muse Code
Agent runtime
Bex Security
Security orchestration
More than a prompt
Muse explores likely attack paths while Bex runs bounded review assignments and advances coverage only after completed, non-truncated reads.
Define source boundaries and permissions before investigation begins.
Use Muse Spark to investigate suspicious data flows and vulnerable code paths.
Challenge candidate findings and reject claims that lack support.
Preserve reviewable findings, evidence, and coverage as local artifacts.
The Bex layer
The community adapter opens Muse to Bex without pretending Muse exposes every ACP capability.
Bex launches Muse through @bex-co/muse-code-acp and forwards the scoped security workbench over ACP.
Host-managed assignments compensate for unavailable delegated workers and count only verified file reads toward coverage.
Muse owns login and model configuration; Bex neither stores the Muse session nor broadens its access.
Quick setup
Install Bex Security and Muse Code, authenticate Muse once, then select the Muse agent with no extra orchestration flag.
Install @bex-co/bex-security from npm and make sure a supported muse binary is available on PATH.
Run muse login once. Muse Code owns the account, model access, and saved configuration used by the scan.
Pass --agent muse. Add --model muse-spark-1.2-contributor and --effort high when those options are available to your account.
No. Bex Security ships with the Bex-maintained community Muse ACP adapter. You still need Muse Code installed and authenticated.
No. Muse's headless interface resolves approvals internally and reports policy decisions, but it cannot pause each tool call for an ACP client confirmation.
Bex runs bounded host-managed review assignments and advances file coverage only for completed, non-truncated read operations it can verify.
Install Bex Security to run Muse inside a bounded workflow that records coverage and validates findings before publication.
Star Bex SecurityOne workflow · Open agent layer · Validated evidence