Aegis: Autonomous Defense Loop reads a deploy, joins misconfigurations into attack paths, hardens the files, and rescans to prove the path is closed. It is for someone who ships a service and wants to see how it can be reached before that path is used.
Stages 01–04 scan a demo deploy, join the findings into paths, edit a copy of the files, and watch for a path that opens again. A fix counts only when the rescan is clean. Stage 05 compares Northwind Checkout with a short-lived sandbox process. Stage 06 is Sentinel. Stage 07 reads a live URI.
Guild supplied Sentinel. One command sends a file to a model and can write a hardened copy. Another turns a log into one incident report. Stage 06 lists both. They need `OPENAI_API_KEY`.
Akash hosts the container. `deploy/lane-demo.sdl.yml` pulls `ankura/lane-demo:0.1.0`. Stage 07 reads that URI. Checked locally, nginx showed HTTP, missing browser headers, and a `Server` header. Lane-demo also showed `/.env`, `/debug`, `/server-status`, and wildcard CORS.
Semgrep 1.180.0 scanned the project. The result is at [https://uboqmsd1v5crh79mno8uca21qg.ingress.boogle.cloud/semgrep-report.html](https://uboqmsd1v5crh79mno8uca21qg.ingress.boogle.cloud/semgrep-report.html): 1 error (`USER root` in the Northwind Dockerfile) and 5 warnings. Three other rules did not run because they need the Semgrep Pro engine.