tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Aegis: Autonomous Defense Loop
securitydevabout 2 hours agoBuilderJudging locked: Event build

Aegis: Autonomous Defense Loop

Aegis reads a deploy you already ship, joins misconfigurations into attack paths, hardens the files, and rescans the workspace and the published URI to prove the path is closed.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Aegis: Autonomous Defense Loop reads a deploy, joins misconfigurations into attack paths, hardens the files, and rescans to prove the path is closed. It is for someone who ships a service and wants to see how it can be reached before that path is used. Stages 01–04 scan a demo deploy, join the findings into paths, edit a copy of the files, and watch for a path that opens again. A fix counts only when the rescan is clean. Stage 05 compares Northwind Checkout with a short-lived sandbox process. Stage 06 is Sentinel. Stage 07 reads a live URI. Guild supplied Sentinel. One command sends a file to a model and can write a hardened copy. Another turns a log into one incident report. Stage 06 lists both. They need `OPENAI_API_KEY`. Akash hosts the container. `deploy/lane-demo.sdl.yml` pulls `ankura/lane-demo:0.1.0`. Stage 07 reads that URI. Checked locally, nginx showed HTTP, missing browser headers, and a `Server` header. Lane-demo also showed `/.env`, `/debug`, `/server-status`, and wildcard CORS. Semgrep 1.180.0 scanned the project. The result is at [https://uboqmsd1v5crh79mno8uca21qg.ingress.boogle.cloud/semgrep-report.html](https://uboqmsd1v5crh79mno8uca21qg.ingress.boogle.cloud/semgrep-report.html): 1 error (`USER root` in the Northwind Dockerfile) and 5 warnings. Three other rules did not run because they need the Semgrep Pro engine.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • AAkash
  • SSemgrep
Tools used
  • Guild.ai logoGuild.ai
  • AAkash
  • SSemgrep