shipwithjev

Catalog / Triage & routing

0613GitHub

momus: staged Rust code and security review

A fast scanner that reviews code for correctness, security, reliability, compatibility and test gaps, with actionable feedback. Supports the Jev API and local models.

brianluby/momus-reviewREADME ↗
# Momus Review

Finds fault in the gods' own work — so it can find fault in yours.

Momus (Μῶμος) is the Greek god of satire, mockery, and criticism. Legend has
it he criticized Zeus's own creations. `momus` is a code/security review
product that does the same to your diffs: fast, calibrated, staged judgments
with concrete evidence, severity, and owner routing.

- Crate: `momus-review` (free on crates.io as of 2026-09-25)
- Binary: `momus`
- Engine: [TypeSafe Jev](https://typesafe.ai), through a thin HTTP client
  speaking the `system_one` wire format directly (see `docs/rust-types.md`)
- Status: the core funnel (`review`/`scan`/`dashboard`) shipped in Rust and
  validated on OWASP Juice Shop through a golden-set eval harness
  (`momus-eval`), with evidence excerpts, an OWASP-aligned security mechanism
  vocabulary, and crypto/misconfig screen steering; pull requests get inline
  review comments through a GitHub Action (see "CI")

## What It Does

Two modes, one funnel:

- `momus review` — review the current Git diff (tracked changes + untracked files)
- `momus scan` — scan every non-ignored source file under a scope

plus `momus github-review` to publish a review to its pull request (see
"CI") and `momus dashboard` to browse the latest report locally.

Both accept one or more scope directories (unioned into one run) plus
`--exclude GLOB` (skip vendored/third-party subtrees), `--follow-ups N`
(opt into a follow-up budget; unlimited by default),
`--fail-on-blocking` (CI exit contract), `--no-refine` (skip the
refinement stage below), `--no-cache` (bypass saved answers), and `--no-redact` (send code without secret
redaction; see below).

`momus review --base REV` diffs against the merge base of `REV` and `HEAD`
instead of `HEAD`: the branch's commits plus uncommitted chan

Also filed under Triage & routing

  1. 0602

    Jevops: SRE log triage with Jev

    Jev triages streaming logs into page, digest or resolve, cutting alert noise and paging humans only for high-confidence incidents. About $1–3 for 1M events a month.

    Mu99Ti · Triage & routing · $1–3 per 1M events/month

  2. 0598

    jev-sec-audit: flag risky npm packages with Jev

    npm install is the scariest command in your terminal. One typo → lookalike package → malicious postinstall → secrets gone. jev-sec-audit flags it in milliseconds using Jev, a System 1 model built for fast decisions, not chat. One step in GitHub Actions. Open source.

    @Dhanush_Nehru · Triage & routing

  3. 0555

    Jev Codex Router: model and reasoning selection per call

    A local Codex router asks Jev to choose the next model and reasoning effort while forwarding the complete conversation to that model.

    0xNatoshi · Triage & routing

  4. 0554

    Jev Search: choose sources and rank web results

    Jev selects search sources and time ranges, then scores result relevance in a multi-engine search app with editable filters.

    superagents-lab · Triage & routing