tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. closedloop
Manvender Rapariaabout 2 hours agoBuilderJudging locked: Event build

closedloop

CloseLoop is an autonomous remediation agent for security teams: it takes a vulnerability finding, writes the fix, proves the exploit works before and is blocked after on a live environment, and ships the verified change as a GitHub PR with audit-ready evidence.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo video
Demo video
Watch demo video
Project description
AI can already suggest security patches, but nobody proves they work before they ship. The Frontier AI cybersecurity survey (arXiv:2504.05408) found zero systems for remediation deployment. CloseLoop fills that gap: Find → Fix → Prove → Ship. How it works: a scanner or red-team agent posts a finding to CloseLoop's handoff API. OpenAI generates a least-privilege patch, which runs through an offline check (up to 3 retries). A Guild AI reviewer agent approves or rejects it. Approved patches are applied to a live lab on Akash, and CloseLoop replays the real exploit: it must succeed before the fix and be blocked after, while canary and app health checks stay green. If anything breaks, it rolls back automatically. Verified fixes ship as a GitHub PR that changes only the affected policy line, with the before/after evidence attached. Tech: OpenAI for patch generation; Guild AI as the independent reviewer agent; Akash to host the live target environment and apply changes via its Console API; ClickHouse to record every pipeline event and evidence trail; GitHub for automated PR shipping. Built with Next.js and TypeScript, 56 tests passing. Results: 4 verified end-to-end runs, each opening a real infra PR, plus a passing rollback test. The recorded run went from finding to verified fix in 1 minute 38 seconds.
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
Project gallery
Project links
  • GitHub repository
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep