# medusa を Homebrew, apt, dnf, MacPorts, Nix, pacman でインストール

medusa のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:medusa
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install medusa
```

  証拠: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install medusa
```

  証拠: MacPorts ports tree: security/medusa/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- Debian apt (92%):

```sh
sudo apt install medusa
```

  証拠: Debian stable package indexes: medusa from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install medusa
```

  証拠: Fedora Rawhide package metadata: medusa from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#medusa
```

  証拠: nixpkgs package indexes: pkgs/by-name/me/medusa/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S medusa
```

  証拠: Arch Linux sync databases: medusa from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

## パッケージ情報

- **パッケージキー:** brew:medusa
- **パッケージマネージャ:** Homebrew
- **パッケージマネージャページ:** <https://formulae.brew.sh/formula/medusa>
- **バージョン:** 1.5.1
- **ソース概要:** Solidity smart contract fuzzer powered by go-ethereum
- **ホームページ:** <https://secure-contracts.com/program-analysis/medusa/docs/src/>
- **リポジトリ:** <https://github.com/crytic/medusa>
- **上流ドキュメント:** <https://secure-contracts.com/program-analysis/medusa/docs/src/>
- **ライセンス:** AGPL-3.0-only
- **ソースアーカイブ:** <https://github.com/crytic/medusa/archive/refs/tags/v1.5.1.tar.gz>
- **最終更新:** 2026-07-29T17:04:53+02:00
- **生成日時:** 2026-08-04T22:13:35+00:00

## 実行可能ファイル

- medusa (cli)
- medusa (エイリアス)

## 依存関係

- crytic-compile

## ビルド依存関係

- go

## インストール挙動

- post-install フック: 未定義
- Bottle: 利用可能 対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## バージョンと鮮度

- ページ生成日: 2026-08-04
- マネージャ版: 1.5.1
- マネージャ更新日: 2026-07-29
- ローカルデータ: OK
- 上流リポジトリ: https://github.com/crytic/medusa
- 検出された最新: v1.5.1 (最新)
## プロジェクトの歴史と使われ方

medusa is a cross-platform, go-ethereum-based smart-contract fuzzer from the Crytic ecosystem. Its official README describes it as inspired by Echidna and designed for parallelized fuzz testing through a CLI or Go API.

### プロジェクトの歴史

The official repository was created in 2023 and its first GitHub release was v0.1.0 in March 2023. The project entered a security tooling space already shaped by Crytic tools such as Echidna and Slither, but focused on a Go implementation powered by go-ethereum.

The documentation grew into a mdBook under Trail of Bits' Building Secure Contracts material, with sections for installation, first steps, project configuration, CLI commands, fuzzing lifecycle, invariant testing, cheatcodes, and an evolving Go API.

### 採用の歴史

medusa is a specialized package for smart-contract auditors, protocol teams, and Solidity developers who need fuzzing in local or CI workflows. Official installation docs include Go install, Homebrew, Nix, Docker, source builds, and precompiled binaries, which is a strong signal that the project expects package-manager and automation use.

The package input lists Homebrew, Debian, Fedora, MacPorts, Nix, Pacman, and Ubuntu package names, showing that the tool has moved beyond a source-only security project into normal developer-tool distribution channels.

### 使われ方

Users initialize a Solidity project with `medusa init`, which creates `medusa.json`, then run campaigns with commands such as `medusa fuzz --target-contracts ... --test-limit ...`. Official docs recommend placing target contracts and fuzz limits in the project configuration file.

### パッケージ好きにとっての重要性

medusa is interesting to package maintainers because it brings smart-contract fuzzing into a single Go CLI while still interoperating with common Ethereum tooling such as crytic-compile, Slither, Foundry, Hardhat, and go-ethereum. It sits in the same toolbox category as Echidna and Slither, but with a distinct implementation and parallel fuzzing model.

### タイムライン

- 2023: Repository is created and v0.1.0 is released.
- 2023: Documentation describes `medusa init`, `medusa fuzz`, and `medusa.json` project configuration workflows.
- 2026: GitHub repository lists v1.5.1 as the latest release.

### Related projects

- medusa is related to Echidna, go-ethereum, crytic-compile, Slither, Foundry, Hardhat, and Trail of Bits' Building Secure Contracts documentation.

### ソース

- <https://api.github.com/repos/crytic/medusa>
- <https://api.github.com/repos/crytic/medusa/releases>
- <https://github.com/crytic/medusa>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/cli/init.md>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/getting_started/first_steps.md>
- <https://raw.githubusercontent.com/crytic/medusa/master/docs/src/getting_started/installation.md>
- <https://secure-contracts.com/program-analysis/medusa/docs/src/>


## セキュリティノート

narrow executable package without higher-risk signals.

- **Geiger リスク:** グリーン / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: medusa.json
## ソースデータベース詳細

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** medusa
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Conflicts With:** bash-completion
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## 他のパッケージマネージャ記録

- Debian apt - medusa - 2.3-2: normalized package name match | Debian stable package indexes: medusa from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | fast, parallel, modular, login brute-forcer for network services | http://foofus.net/?page_id=51
- Nix - medusa: normalized package name match | nixpkgs package indexes: pkgs/by-name/me/medusa/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - medusa - 2.2-7build3: normalized package name match | Ubuntu 24.04 LTS package indexes: medusa from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | fast, parallel, modular, login brute-forcer for network services | http://foofus.net/?page_id=51
- dnf - medusa - 2.3-8.20240130git4e9be7e.fc45: normalized package name match | Fedora Rawhide package metadata: medusa from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | Speedy, parallel, and modular, login brute-forcer | http://www.foofus.net/jmk/medusa/medusa.html
- pacman - medusa - 2.2-13: normalized package name match | Arch Linux sync databases: medusa from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Speedy, massively parallel and modular login brute-forcer for network | http://www.foofus.net/jmk/medusa/medusa.html
- MacPorts - medusa: normalized package name match | MacPorts ports tree: security/medusa/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1


## 関連リンク

- [Terminal utility packages](https://pkg.so/ja/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Language runtime packages](https://pkg.so/ja/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [Networking and protocol packages](https://pkg.so/ja/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/ja/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [crytic-compile](https://pkg.so/ja/brew/crytic-compile/) - Runtime dependency declared by Homebrew.
- [go](https://pkg.so/ja/brew/go/) - Build dependency declared by Homebrew.
- [radamsa](https://pkg.so/ja/brew/radamsa/) - Shares pkgdb curated category or tags: cli, fuzzer, fuzzing, security, security-testing.
- [ffuf](https://pkg.so/ja/brew/ffuf/) - Shares pkgdb curated category or tags: cli, fuzzing, security.
- [echidna](https://pkg.so/ja/brew/echidna/) - Shares pkgdb curated category or tags: cli, fuzzing, security, security-testing, smart-contracts.
- [slither-analyzer](https://pkg.so/ja/brew/slither-analyzer/) - Shares pkgdb curated category or tags: cli, security, smart-contracts, solidity.
- [afl++](https://pkg.so/ja/brew/afl/) - Shares pkgdb curated category or tags: cli, fuzzing, security, security-testing.
- [dnsgen](https://pkg.so/ja/brew/dnsgen/) - Shares pkgdb curated category or tags: cli, security, security-testing.
- [proxelar](https://pkg.so/ja/brew/proxelar/) - Shares pkgdb curated category or tags: cli, security, security-testing.

## Combined YAML source

View the package source record on GitHub. [combined/medusa.yml](https://github.com/mxcl/pkgdb/blob/main/combined/medusa.yml)


## ソース

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
