OpenAI 2026 hackathon

AgentShield

AgentShield detects and blocks AI agent threats — prompt injection, data leaks, and shadow agents — in real-time across your entire organization.

Solo project by Chia Stanley Mbeng · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #541 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be: AgentShield is an open-source runtime security platform for detecting and blocking AI agent threats — including prompt injection, data leaks, and shadow agents — in real-time across organizations. It intercepts LLM traffic through a lightweight sidecar proxy with three detection layers: regex-based (L1), semantic similarity (L2), and LLM-based judgment (L3). The platform also includes a scanner for unauthorized AI agents running on employee machines.

What changed: The project was submitted to the OpenAI 2026 hackathon by a single founder, Chia Stanley Mbeng. It is described as an MVP with full functionality across all components, including Windows support and one-command installation. It has no revenue or customer data, but the author claims it is production-ready and open-source.

Single most important open question: Is there any evidence of real-world adoption or traction beyond the author’s own development?

Back to contents

What The Product Actually Is

The description states that AgentShield is an open-source runtime security platform designed to protect organizations from AI agent threats. It operates by:

  • Intercepting LLM traffic through a lightweight sidecar proxy (written in Go).
  • Applying three detection layers:
    • L1: Regex engine blocking known attack patterns.
    • L2: Semantic detection using sentence-transformers to detect novel attacks.
    • L3: Asynchronous LLM judge using Ollama and TinyLlama for deep analysis of borderline cases.
  • Including a Shadow Agent Discovery scanner that monitors for unauthorized AI agents on employee machines, scanning processes, ports, and network connections.
  • Providing a dashboard (React + Vite) showing live events with threat scores, flagged agents, and controls.

The author claims the system is built for production use, deployable in minutes via a single command, and fully functional on Windows.

Evidence: Self-reported by the author. No independent verification or data on actual deployment or usage.

Back to contents

Positioning & Claim Evolution

The author positions AgentShield as a solution to a critical blind spot in AI security, where organizations are deploying AI agents without oversight. The core claim is that:

  • The attack surface has shifted from traditional networks to LLM API calls.
  • Current security tools are outdated and cannot detect emerging threats like prompt injection or shadow agents.
  • AgentShield fills this gap with a layered, extensible architecture.

The project’s evolution appears to be from a hackathon MVP to a production-ready platform with future plans for enterprise features, cloud management, and community threat intelligence.

Evidence: Self-reported. No data on prior versions or market feedback.

Back to contents

Target Customer & ICP

The description states that AgentShield targets organizations deploying AI agents powered by LLMs, especially those with:

  • Mid-size SaaS companies (as cited in the inspiration story).
  • Employees using AI agents with access to production systems.
  • A need for real-time detection of threats like prompt injection, data leaks, and unauthorized shadow agents.

The author notes that enterprise endpoints often run Windows, suggesting a focus on Windows-based enterprise environments.

Evidence: Self-reported. No evidence of actual customers or customer segmentation.

Back to contents

Business Model & Pricing Evidence

There is no mention of pricing, licensing, or monetization in the description. The project is described as open-source, and the author states that it is “live on GitHub” with public code and architecture.

Evidence: Self-reported. No evidence of revenue model or pricing structure.

Back to contents

Technical & Delivery Signals

The system is built using:

  • Go for the sidecar proxy.
  • Python + sentence-transformers for semantic detection.
  • Ollama + TinyLlama for LLM-based judgment.
  • React + Vite for the dashboard.
  • Windows PowerShell for deployment and service management.

Key technical features include:

  • Sub-50ms latency in most requests.
  • Asynchronous processing for L3 detection.
  • One-command installation on Windows.
  • SQLite backend with REST APIs.
  • Shadow agent discovery scanning every 15 minutes.

The author claims the system is fully functional, passing all smoke tests and deployable in under 5 minutes.

Evidence: Self-reported. No evidence of performance data, scalability, or production deployment beyond the author’s own testing.

Back to contents

Traction & Maturity Signals

The project is described as an MVP with:

  • 6/6 smoke tests passing.
  • One-command install.
  • Live on GitHub (open-source).
  • Fully functional on Windows.
  • No revenue or customer data provided.

There is no evidence of actual users, adoption, or market traction beyond the author’s own development.

Evidence: Self-reported. No third-party validation or usage metrics.

Back to contents

Competitive Context

The author states that:

  • The AI security space is a greenfield market with no dominant players.
  • Major vendors like Microsoft, CrowdStrike, and Palo Alto are racing to build similar solutions.
  • AgentShield aims to be a layered, extensible architecture that can evolve as attacks evolve.

No specific competitors or competitive positioning beyond general market claims are mentioned.

Evidence: Self-reported. No data on existing products or competitive analysis.

Back to contents

Key Risks & Red Flags

  • Single-founder project with no team or external validation.
  • No revenue, customers, or traction — all self-reported.
  • Open-source model may limit monetization and enterprise adoption unless further developed.
  • Windows-only support may limit market reach despite the author’s claims of importance.
  • Async L3 architecture introduces complexity and potential race conditions.
  • Shadow agent detection is described as having false positives, with no clear mitigation strategy.

Evidence: Self-reported. No external validation or risk assessment data.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific threats have you observed in real-world environments?
  2. How do you plan to monetize the open-source platform?
  3. Have you conducted any security audits or penetration testing on the system?
  4. What is your roadmap for enterprise features and scalability?
  5. How do you intend to manage false positives in shadow agent detection?
  6. Are there any known limitations of the current architecture that could affect performance at scale?

Back to contents

Investment/Partnership Verdict

AgentShield is a self-reported MVP with a clear technical vision, but no evidence of traction, revenue, or customer adoption. The project is described as production-ready and open-source, with strong technical execution on Windows and latency optimization.

However, due to the lack of any third-party validation, user data, or commercial activity, it is not ready for investment or partnership consideration at this time.

Confidence: Low — based entirely on self-reported claims.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.