tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Rootlane
David Jimenez Moraabout 2 hours agoContributorJudging locked: Event build

Rootlane

An autonomous security agent that continuously watches a live web app, investigates what looks wrong with cited evidence, and proposes a fix that a named human approves before it ships.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project website
Demo video
Watch demo video
Project description
OWASP Top 10:2025 ranks Broken Access Control #1: 100% of the applications tested had some form of it. Alerts do not fix anything and unverified patches are guesses. Rootlane closes the loop. Our OWASP Juice Shop (juiceshop.rootlane.xyz, Akash) sends derived request telemetry (never passwords, tokens or bodies) to the Rootlane API (api.rootlane.xyz, FastAPI on Akash), stored in ClickHouse Cloud. Every ~10 s an always-on open model on AkashML (GLM-5.3) reads behavioural features per identity and IP and answers ignore / watch / escalate; a deterministic rule also escalates when an identity is served without ever logging in. Escalation opens an incident and starts our TypeScript agent hosted on Guild (claude-opus-5): it queries ClickHouse read-only, reads the source, runs Semgrep and cites our policies stored in Senso; every tool call is audited. It proposes a fix plus a Semgrep rule; a named human approves in the dashboard (app.rootlane.xyz, Vercel) and it opens a PR on our fork. Guild hosts and governs the agent. ClickHouse is the real-time backbone. Akash hosts the app and API; AkashML runs triage. Senso is the verified context. Semgrep scans, verifies and prevents recurrence. Replica verification is built but disabled on the public deploy for safety.
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai
Watch demo video
Project gallery
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • SSenso.ai