tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Agent Immune System with Causal Guardrails
Aj Moulyabout 2 hours agoContributorEvent build

Agent Immune System with Causal Guardrails

A runtime defense for AI agents that detects a prompt-injection hijack, proves which input caused it, and deploys a guardrail verified against all recorded history before it ships.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Agent Immune System (AIS) is a runtime defense for AI agents. Agents act on whatever is in their context, so an attacker can hide instructions in a retrieved document or support ticket and make the agent exfiltrate data. This is indirect prompt injection, the defining attack surface for agents. Detection tools raise an alert but never say which input caused it or how to fix it. AIS closes that gap in one loop. When a session is flagged, AIS does 3 things that most defenses miss. First, AIS detects from provenance flow, not keywords, so that an external send of sensitive data while untrusted input is present is stopped fast and hard.  Second, Causal replay re-runs the session with each untrusted input removed to prove the exact input responsible. Third, AIS vaccinates with an open model on AkashML that generates evasive variants, a guardrail is synthesized, and it is verified against the entire recorded corpus in ClickHouse, deploying only on zero false positives. Re-running the attack is then blocked. Live on ClickHouse Cloud on over 601,000 rows.   Detection in ~59 ms, verification in ~74 ms, 9 of 9 variants blocked with 0 false positives. The novel and innovative part is the combination of runtime causal attribution plus auto-remediation regression-tested against production history.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • FastAPI-MCP logoFastAPI-MCP
  • ClickHouse logoClickHouse
  • PPi
  • AAkash
  • SSemgrep
  • SSenso.ai
  • PPython
Tools used
  • Guild.ai logoGuild.ai
  • FastAPI-MCP logoFastAPI-MCP
  • ClickHouse logoClickHouse
  • PPi
  • AAkash
  • SSemgrep
  • SSenso.ai
  • PPython