Cognium
Traces tainted data across functions, files, and frameworks to detect vulnerabilities like SQL injection, command injection, and XSS.
A deterministic semantic static analysis engine that traces tainted data across functions, files, and frameworks to identify real vulnerabilities in AI-written code. It serves developers, IT teams, and security teams in enterprises adopting AI-generated code. The engine is open-source, MIT licensed, and runs locally without a server or LLM tokens, with optional model-assisted discovery. It is delivered as a CLI, a Node/browser library, and an MCP server for integration into terminals, CI, products, or AI agents.
Key features
- Source detection for HTTP parameters, headers, cookies
- Inter-procedural taint tracking across calls and fields
- Sanitizer awareness with YAML custom definitions
- Framework-aware rules for Java, JavaScript, Python, Go
- Covers 19 CWE types including SQLi, XSS, SSRF
- Runs in terminal, CI, browser, or as MCP server
- Deterministic and reproducible without LLM
- Optional model-assisted discovery for deeper research
- No social media activity within the last 30 days
GTM channels
- Community
- API
- Docs
ICP
- Security teams
- Software developers
- Engineering teams
Vendorcognium.dev