Sentinel turns a library's biggest blind spot into a feedback loop.
When an open-source library has a vulnerability, its maintainer is flying blind — they can't see how it's used in the wild, or that it's under attack, until it's a headline (Log4Shell, XZ Utils). Sentinel closes that loop.
Three apps — a chat unfurler, a webhook fetcher, an admin image proxy — all depend on one shared linkpreview library with an SSRF vulnerability. A scout inside each app reports every call and attack to HQ, streaming into ClickHouse as a live signal. When the fleet gets hit, an autonomous agent reads the evidence, writes a hardened library on an open model via Akash, and self-verifies the fix in a sandbox before shipping: it proves the patch blocks the attacks and still allows real URLs. If the model hallucinates a bad fix, the agent rejects it. It never ships a fix it hasn't tested. Then it opens a real GitHub pull request and hot-deploys.
The result: the same attacks, re-run, are all blocked — and no app changed a single line of its own code. One fix, at the library, protects the whole fleet at once.
The agent is hosted and runs on Guild. We used Semgrep to catch a real SSRF bypass in AI-generated code — a short-form-loopback trick — exactly the bug the self-verify step stops from shipping.
Fix once, protect everyone.