momus: staged Rust code and security review
A fast scanner that reviews code for correctness, security, reliability, compatibility and test gaps, with actionable feedback. Supports the Jev API and local models.
# Momus Review Finds fault in the gods' own work — so it can find fault in yours. Momus (Μῶμος) is the Greek god of satire, mockery, and criticism. Legend has it he criticized Zeus's own creations. `momus` is a code/security review product that does the same to your diffs: fast, calibrated, staged judgments with concrete evidence, severity, and owner routing. - Crate: `momus-review` (free on crates.io as of 2026-09-25) - Binary: `momus` - Engine: [TypeSafe Jev](https://typesafe.ai), through a thin HTTP client speaking the `system_one` wire format directly (see `docs/rust-types.md`) - Status: the core funnel (`review`/`scan`/`dashboard`) shipped in Rust and validated on OWASP Juice Shop through a golden-set eval harness (`momus-eval`), with evidence excerpts, an OWASP-aligned security mechanism vocabulary, and crypto/misconfig screen steering; pull requests get inline review comments through a GitHub Action (see "CI") ## What It Does Two modes, one funnel: - `momus review` — review the current Git diff (tracked changes + untracked files) - `momus scan` — scan every non-ignored source file under a scope plus `momus github-review` to publish a review to its pull request (see "CI") and `momus dashboard` to browse the latest report locally. Both accept one or more scope directories (unioned into one run) plus `--exclude GLOB` (skip vendored/third-party subtrees), `--follow-ups N` (opt into a follow-up budget; unlimited by default), `--fail-on-blocking` (CI exit contract), `--no-refine` (skip the refinement stage below), `--no-cache` (bypass saved answers), and `--no-redact` (send code without secret redaction; see below). `momus review --base REV` diffs against the merge base of `REV` and `HEAD` instead of `HEAD`: the branch's commits plus uncommitted chan
