OpenAI 2026 hackathon

AuditPilot

A Codex-native smart contract audit toolkit for Solidity and Solana, with a web app and MCP tools for agent-driven security analysis.

Solo project by Ikpia Emmanuel · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #2,799 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

AuditPilot is a self-reported smart contract security toolkit for Solidity and Solana developers, built as a web app and an MCP server. The author states it uses Codex and GPT-5.6 in its development and offers two surfaces: a hosted web app with GitHub OAuth and OpenAI key storage, and an MCP server that enables agent-driven security analysis without consuming the project’s own API keys.

What changed

The description indicates a working prototype built during a hackathon, with core functionality including GitHub authentication, encrypted API key handling, audit history tracking, and an MCP server for deterministic reasoning. It is not evidenced whether this has progressed beyond prototype or gained users.

The single most important open question

Is there any evidence of real-world usage or adoption by developers? The description states no revenue, customers or traction data are available.

Back to contents

What The Product Actually Is

The description states that AuditPilot is a smart contract audit toolkit for Solidity and Solana. It has two components:

  1. A web app, where developers sign in with GitHub, securely store their own OpenAI API key, run audits, and view audit history.
  2. An MCP server, which allows Codex, IDE agents, or ChatGPT to use AuditPilot as a deterministic security toolkit.

The MCP server exposes three tools:

  • clone_and_parse_contract
  • get_vulnerability_checklist
  • search_solodit_findings

The author states that the MCP reasoning happens inside the developer’s own Codex session, and that the project does not spend its own OpenAI key. The web app uses GPT-5.6 when a signed-in user provides their own API key.

Inference The product is a hybrid tool combining a hosted interface with an agent-integrated backend, designed for developer workflow integration.

Back to contents

Positioning & Claim Evolution

The author states that smart contract teams need fast security feedback before formal audits, but existing tools are often chain-specific, expensive, or shallow. AuditPilot was built to make Codex useful as a security assistant for Solidity and Solana developers.

Claim

The product is positioned as a tool that enhances developer workflows by integrating with Codex and offering deterministic security analysis via an MCP server.

Inference The positioning reflects a niche in developer tooling, targeting early-stage smart contract development teams seeking rapid feedback. No evidence of market positioning beyond the author's own description.

Back to contents

Target Customer & ICP

The author states that AuditPilot is for Solidity and Solana/Anchor developers, who need fast security feedback before formal audits.

Inference The target customer segment appears to be early-stage or mid-tier smart contract developers working in Ethereum and Solana ecosystems, who are looking for lightweight, agent-integrated audit tools.

Not evidenced No specific customer personas, use cases, or adoption data are provided.

Back to contents

Business Model & Pricing Evidence

The description does not state a business model or pricing structure. It mentions that users sign in with GitHub, store their own OpenAI API key, and run audits via the web app.

Inference The product appears to be free-to-use, with no explicit monetization mechanism described. The web app is hosted, but there’s no indication of paid tiers or subscriptions.

Back to contents

Technical & Delivery Signals

The author states that the project was built using:

  • Frameworks: Next.js, React, TypeScript
  • Tools: Codex, GPT-5.6, Supabase, GitHub OAuth, Anchor, Solana, Solidity, Solodit, Cyfrin
  • Infrastructure: Vercel, OpenAI API

Key technical decisions include:

  • The MCP server is deterministic, not calling the project’s own model key.
  • The web app uses GPT-5.6 with a BYOK (Bring Your Own Key) approach.
  • GitHub OAuth and encrypted storage of user keys are implemented.
  • Audit history is persistent.

Inference The technical stack suggests a developer-focused, lightweight tool built in a short timeframe, likely during a hackathon.

Back to contents

Traction & Maturity Signals

The description states that the project was submitted to the OpenAI 2026 hackathon, and includes accomplishments such as:

  • A working Next.js web app
  • Supabase GitHub OAuth
  • Encrypted per-user OpenAI key storage
  • Persistent audit history
  • MCP server with local testing against foundry-rs/forge-std
  • Solodit/Cyfrin historical finding lookup

Not evidenced No user base, revenue, or adoption metrics are provided. The project is described as a prototype.

Back to contents

Competitive Context

The author states that existing tools are often chain-specific, expensive, or shallow, and that AuditPilot aims to make Codex useful for security analysis.

Inference The competitive landscape includes traditional audit platforms (e.g., Cyfrin, Solodit) and other developer tooling. However, no specific competitors or market positioning beyond the author’s own claims are stated.

Back to contents

Key Risks & Red Flags

  • No traction or revenue data: The project is described as a hackathon prototype with no evidence of real-world usage.
  • Dependency on external tools: Reliance on GitHub OAuth, Supabase, and OpenAI API keys raises concerns about scalability and control.
  • MCP server design choice: The decision to keep reasoning client-side may limit the tool’s utility or performance.
  • Single-founder team: The project is built by one person, which may affect long-term development and support.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current usage of AuditPilot? Are there any users or feedback from developers?
  2. How does the product plan to scale beyond a hackathon prototype?
  3. Is there a clear path to monetization, or is it intended as an open-source tool?
  4. What are the limitations of the current MCP implementation and how might they be addressed?
  5. Are there any plans for additional chain support (e.g., Move, CosmWasm)?
  6. How does the project handle GitHub rate limits and API key security in a production environment?

Back to contents

Investment/Partnership Verdict

Not evidenced: No financials, customer data, or traction metrics are provided.

Inference The project is currently a prototype, built during a hackathon with no evidence of commercial adoption or revenue. It shows early technical capability but lacks the signals typically required for investment or partnership consideration.

The author’s own description indicates that the product is in an early stage and has not yet reached market traction. It may be a promising idea, but there is no evidence of real-world usage or commercial viability at this time.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.