An autonomous security researcher for engineering teams: a git push triggers a Semgrep scan, a Pi agent writes a proof of concept and fix, a Guild sandbox proves the bug and verifies the patch, and only hard evidence opens a draft PR.
0DayForge is an autonomous security remediation harness. A push to the `demo` branch of an owned GitHub repository starts a run with no manual prompt: a pinned Semgrep scan produces a candidate, the Pi SDK proposes a hypothesis, a benign proof of concept, a regression test and a unified-diff patch, and all three are executed inside an isolated Guild.ai sandbox. The original copy must reproduce the issue, the patched copy must block the identical PoC, and the functional tests must still pass. Every stage is persisted to ClickHouse for deduplication and an auditable timeline.