Documentation
Hands-on tutorials.
Install the engine, scan a repository, add a pull-request security gate, and give Cursor deterministic security tools. Every example uses public packages and repositories.
Choose a workflow.
Start locally, carry the same scan into CI, then expose the deterministic engine to your coding agent through MCP.
01 · 15 min
Your first security scan
Install cognium-dev, scan source code, interpret a taint trace, and export SARIF.
Gate pull requests
Run the public Cognium Action, upload SARIF, and enforce high-severity findings.
Start tutorial → 03 · 10 minCursor + MCP tools
Configure all eleven Cognium MCP tools so the agent calls the engine instead of guessing.
Start tutorial →Open-source scope: These tutorials cover the MIT-licensed
cognium-dev engine. Product-level verification and policy workflows live at cognium.net.