Skip to content
Home

Cognium

Traces tainted data across functions, files, and frameworks to detect vulnerabilities like SQL injection, command injection, and XSS.

A deterministic semantic static analysis engine that traces tainted data across functions, files, and frameworks to identify real vulnerabilities in AI-written code. It serves developers, IT teams, and security teams in enterprises adopting AI-generated code. The engine is open-source, MIT licensed, and runs locally without a server or LLM tokens, with optional model-assisted discovery. It is delivered as a CLI, a Node/browser library, and an MCP server for integration into terminals, CI, products, or AI agents.

Key features

  • Source detection for HTTP parameters, headers, cookies
  • Inter-procedural taint tracking across calls and fields
  • Sanitizer awareness with YAML custom definitions
  • Framework-aware rules for Java, JavaScript, Python, Go
  • Covers 19 CWE types including SQLi, XSS, SSRF
  • Runs in terminal, CI, browser, or as MCP server
  • Deterministic and reproducible without LLM
  • Optional model-assisted discovery for deeper research
  • No social media activity within the last 30 days
GTM channels
  • Community
  • API
  • Docs
ICP
  • Security teams
  • Software developers
  • Engineering teams
Vendorcognium.dev