tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. sentinalCYBER
kkoratkaabout 2 hours agoContributorJudging locked: Event build

sentinalCYBER

Sentinel puts a scout in every app that uses a library, streams real-world attacks to HQ, and an autonomous agent hardens the library itself, verifies the fix, and opens a PR, so one patch protects every dependent app at once.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
Sentinel turns a library's biggest blind spot into a feedback loop. When an open-source library has a vulnerability, its maintainer is flying blind — they can't see how it's used in the wild, or that it's under attack, until it's a headline (Log4Shell, XZ Utils). Sentinel closes that loop. Three apps — a chat unfurler, a webhook fetcher, an admin image proxy — all depend on one shared linkpreview library with an SSRF vulnerability. A scout inside each app reports every call and attack to HQ, streaming into ClickHouse as a live signal. When the fleet gets hit, an autonomous agent reads the evidence, writes a hardened library on an open model via Akash, and self-verifies the fix in a sandbox before shipping: it proves the patch blocks the attacks and still allows real URLs. If the model hallucinates a bad fix, the agent rejects it. It never ships a fix it hasn't tested. Then it opens a real GitHub pull request and hot-deploys. The result: the same attacks, re-run, are all blocked — and no app changed a single line of its own code. One fix, at the library, protects the whole fleet at once. The agent is hosted and runs on Guild. We used Semgrep to catch a real SSRF bypass in AI-generated code — a short-form-loopback trick — exactly the bug the self-verify step stops from shipping. Fix once, protect everyone.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep