tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Antibody
Gayathri Ramakrishnanabout 2 hours agoContributorJudging locked: Event build

Antibody

An autonomous agent that finds a real SQL-injection bug with Semgrep, fixes it with Guild AI, verifies the fix via independent tests, then deploys the patched app live and logs tamper-evident proof to ClickHouse — closing a security hole without closing the business.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Antibody is a hackathon project building an autonomous agent that repairs a real SQL-injection flaw in a team-owned OWASP Juice Shop deployment (in routes/search.ts), verifies the fix doesn't break ordinary search, deploys the passing candidate to a live public endpoint, and publishes honest evidence — not just a PR or local demo. Core loop: Agent gets a real Semgrep finding → proposes a patch via Guild AI → host independently validates diff scope and runs locked-down behavior checks (search works, injection fails, scan is clean) → only a fully-passing candidate can deploy (host enforces this even if the agent asks to skip it) → external HTTP probes verify the live endpoint → everything logs to ClickHouse as evidence. A deliberately bad candidate is run through the same gate to prove rejection is real, not staged. Ethos: The docs obsessively close loopholes — no claiming a tool was "used" if only planned, no attributing test candidates to the model falsely, no calling deployment "verified" without an actual probe, no claiming the app is "secure" from a narrow test pass. The host owns credentials and authorization; the model only proposes.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai