GHOST proves your detection works instead of assuming it does.
What we built: six red-team agents (recon, network scan, injection, auth bypass, DoS/resilience, business-logic abuse) run against TowerBank, a deliberately vulnerable sandbox app we built and own. Every action becomes a structured event. ClickHouse scores each event with windowed detection queries, labels it detected or missed, and streams live coverage % and mean-time-to-detect to a 3D siege view: shields flash when an attack is caught, and the tower takes damage when one slips through.
How it works: every event travels two lanes at once. The visual lane (agent, coordinator, WebSocket) never waits on the database. The analytics lane (same event, ClickHouse, verdict) feeds the live stats. A volume replayer preloads millions of historical events so the numbers hold at scale.
Guild.ai: the six agents are built with the Guild Agent SDK, published to Guild, and started as Guild sessions through the Guild API. Each returns a typed event stream that a forwarder posts to the coordinator.
ClickHouse: detection verdicts, coverage and latency are analytical queries over the event table. LibreChat on top lets you ask "which attacks slipped through in the last run?" in plain English.
Semgrep: we scanned our AI-generated target code and wrote up the most interesting finding.