tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Hacker Bot: SENTINEL
Jake Martinabout 1 hour agoContributorEvent build

Hacker Bot: SENTINEL

Hacker Bot is an autonomous defensive-security agent that finds and verifies real vulnerabilities on the open web — where every action it takes, and every tool call from any agent you connect, must first pass a deterministic governance gate that answers EXECUTE or REFUSE, with a signed receipt.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Hacker-Bot is a defensive security agent that does real work on the open web — and provably can't overstep. It runs continuously: monitoring live vulnerability feeds (OSV, NVD, ThreatFox), scanning its own drafts with Semgrep before it writes, and publishing verified advisories — each with the fix and upgrade command — to a live site. Every action crosses a deterministic governance gate that answers EXECUTE or REFUSE. No AI sits in the enforcement path, and both outcomes are written as signed, tamper-evident receipts. An advisory publishes only with two independent corroborating sources. When a CVE has just one source, the agent proves the fix itself: it spins up an ephemeral sandbox container on Akash, fetches the package source at the fixed version and the prior release, and diffs them to isolate the real fix changeset — no untrusted code executed. You watch the containers spin up live. Then it hands you the controls: connect any MCP agent (Claude Code, Cursor) and yours is governed too — it asks check_dependency before adding a dependency, and the gate refuses with the CVE and the fix. Or paste your lockfile to see what hits you. Sponsors: ClickHouse (every decision a queryable row), Semgrep (findings are gate inputs — a custom rule caught a real vuln in AI-generated code), Akash (decision relay + validation sandbox).
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai
Tools used
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai