Skip to main content

Muse Code security scan

Run a Muse Code security scan with validated evidence.

Route Muse Spark through Bex's bundled community ACP adapter while Bex manages repository scope, host review coverage, validation, and artifacts.

Open source · Apache 2.0 · Report-only by default

Muse Code security scan
npm install --global @bex-co/bex-security
muse login
bex-security scan . --agent muse --model muse-spark-1.2-contributor --effort high
Muse CodeMuse Spark 1.2Bex Security

Muse Spark 1.2

Selected model

Muse Code

Agent runtime

Bex Security

Security orchestration

More than a prompt

What a Muse Code security scan actually does.

Muse explores likely attack paths while Bex runs bounded review assignments and advances coverage only after completed, non-truncated reads.

  1. 01

    Scope the repository

    Define source boundaries and permissions before investigation begins.

  2. 02

    Discover attack paths

    Use Muse Spark to investigate suspicious data flows and vulnerable code paths.

  3. 03

    Validate evidence

    Challenge candidate findings and reject claims that lack support.

  4. 04

    Seal scan artifacts

    Preserve reviewable findings, evidence, and coverage as local artifacts.

The Bex layer

Pair Muse Code with a security workflow that checks its work.

The community adapter opens Muse to Bex without pretending Muse exposes every ACP capability.

Open agent boundary

Bex launches Muse through @bex-co/muse-code-acp and forwards the scoped security workbench over ACP.

Stable scan contract

Host-managed assignments compensate for unavailable delegated workers and count only verified file reads toward coverage.

Scoped credentials

Muse owns login and model configuration; Bex neither stores the Muse session nor broadens its access.

Quick setup

How to run a Muse Code security scan.

Install Bex Security and Muse Code, authenticate Muse once, then select the Muse agent with no extra orchestration flag.

1

Install Bex Security and Muse Code

Install @bex-co/bex-security from npm and make sure a supported muse binary is available on PATH.

2

Authenticate Muse

Run muse login once. Muse Code owns the account, model access, and saved configuration used by the scan.

3

Select Muse and its model

Pass --agent muse. Add --model muse-spark-1.2-contributor and --effort high when those options are available to your account.

Alpha integration. Muse support uses an unofficial community adapter. Interactive tool approvals, client-provided MCP servers, delegated workers, and complete usage data are not currently exposed through Muse's headless surface.

Frequently asked questions

Do I need to install muse-code-acp separately?

No. Bex Security ships with the Bex-maintained community Muse ACP adapter. You still need Muse Code installed and authenticated.

Can Bex request interactive Muse tool approvals over ACP?

No. Muse's headless interface resolves approvals internally and reports policy decisions, but it cannot pause each tool call for an ACP client confirmation.

How does Bex track coverage without Muse delegated workers?

Bex runs bounded host-managed review assignments and advances file coverage only for completed, non-truncated read operations it can verify.

Turn Muse Code review into inspectable security evidence.

Install Bex Security to run Muse inside a bounded workflow that records coverage and validates findings before publication.

Star Bex Security

One workflow · Open agent layer · Validated evidence