tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Tripwire
Bindu Bhargava Reddy Chintamabout 2 hours agoBuilderJudging locked: Event build

Tripwire

The immune system for AI-agent fleets. It holds risky agent actions before they run, traces a poisoned input across the fleet, and cures it with a fix proven on ~30M events in ClickHouse.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
AI agents now hold production keys: they read config, run commands and call APIs, and one poisoned ticket can turn an agent into an attacker. Tripwire is the checkpoint every agent tool call passes through, built for security and platform teams running agent fleets in production. • Prevent: risky sends are held and judged by an AkashML model (labelled rule fallback if slow) before they run, so the secret never leaves. • Trip: decoy honeytokens catch exfiltration instantly, with no model call. • Detect: a millisecond ClickHouse funnel over the live stream quarantines an agent that reads a secret, encodes it and sends it out. • Trace: it finds patient zero (the poisoned input), puts every other agent that read it on heightened watch and denies the attacker's host fleet-wide. • Cure with proof: a guardrail ships only after it refuses a sandboxed replay of the attack, keeps normal work running and is backtested over ~30M events in under a second; then a human approves it in Guild. • Explain: an investigator writes the incident report with its own SQL receipts. Every number on screen comes from a receipt. On 60 labelled development cases (not a held-out test) it caught 30/30 attacks with 0 false positives. Guild-hosted agents and any MCP client are governed by the same checkpoint, and Semgrep scanned our own AI-written code: 1 real finding, fixed.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • TBTokens& Build Packet
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
  • SSemgrep
  • TBTokens& Build Packet