tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Kavach
Vaibhav Bhandariabout 1 hour agoContributorJudging locked: Event build

Kavach

Kavach wraps any AI agent in a sandbox, a policy gateway and a secrets vault from one config file, so a prompt-injected agent can't leak card numbers or API keys.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project website
Demo video
Watch demo video
Project description
Kavach (कवच, "armor") is a containment layer for customer-facing AI agents. The model is not the security boundary. Our demo: a refund agent reads a support ticket with a hidden prompt injection telling it to POST the customer's card number to an attacker. Uncontained, it leaks the card and the API key. Inside Kavach, it never sees them. How it works: the agent runs in a sandbox whose only route out is a Kavach gateway (mitmproxy + our add-on). The gateway tokenizes card numbers before the agent sees them and swaps the token back to the real card only on the call to the payment processor. Stand-in API keys are swapped for the real key only on the matching provider's host. A kernel eBPF guard kills any process that tries a raw socket around the gateway. Every request is recorded in a wire log showing what the agent sent versus what left the sandbox, with cards and keys masked.  NVIDIA OpenShell as a second sandbox backend (kavach openshell compile turns the same policy into an OpenShell policy, and OpenShell's own audit events join the wire log), and Kyverno-inspired policy features: audit vs. enforce mode, expiring exceptions, PolicyReport export and CI lint. Verified live on OpenShell 0.1.3, with Qwen3-30B running through the same path. Evidence: kavach eval replays 10 attacks (10/10 clean, refunds still succeed), 40 unit tests, and a 17-check end-to-end suite on a homelab VM.
Tools used
  • PPi
Watch demo video
Project gallery
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • PPi