tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Security Twin
SS HCabout 1 hour agoContributorEvent build

Security Twin

An AI red-team that clones your app, attacks the clone through a shield proxy, detects the breach with a ClickHouse SQL query in ~110ms, confirms it with Semgrep, applies a blast-radius-aware fix, and locks the pattern into CI so the same bug can never re-enter.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Security Twin is a 13-stage autonomous pipeline that finds, fixes, and permanently blocks IDOR vulnerabilities — the access-control bugs AI coding assistants routinely generate. It clones your app into an isolated workspace, sends an LLM attacker (AkashML Llama-3.3-70B or OpenAI) through a shield proxy, then runs one ClickHouse SQL query across 6,802 real HTTP events to spot enumeration in 118ms. The exact vulnerable file is patched with a blast-radius-aware ownership guard. The fix is proved live. A Semgrep rule is auto-generated and committed as a blocking CI gate — so the same bug is rejected in every future PR. Real run: 13 stages in 29 seconds. All live on Vercel. Security teams patch a vulnerability and move on. Two months later a new endpoint re-introduces the exact same pattern. Security Twin breaks that cycle. It clones your app into an isolated workspace so nothing touches productionAn LLM attacker (OpenAI, Nebius, or AkashML) fires real HTTP payloads through a reverse proxy shieldClickHouse detects the attack signature across thousands of events in ~110ms with a single SQL querySemgrep confirms the root cause in source codeThe pipeline applies a blast-radius-aware fix (choosing between a non-breaking guard or a signature change based on how many callers exist)A custom Semgrep memory rule is committed to CI — every future PR that repeats the pattern is blocked automatically
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • ClickHouse logoClickHouse
  • SSemgrep
  • PPi
  • AAkash
Tools used
  • ClickHouse logoClickHouse
  • SSemgrep
  • PPi
  • AAkash