OpenAI 2026 hackathon

BadgeIn x Skybridge

HUMAN AUTHORITY FOR AI ACTIONS. AI can propose. Only you can approve.

Solo project by Saul Lowery · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #2,867 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

BadgeIn x Skybridge is a self-reported system designed to enforce human authority over AI actions in business environments. It is described as a solution to prompt injection vulnerabilities by separating decision-making from language-based execution, using deterministic app manifests, single-use grants, and sandboxed runtime execution.

What changed

The project was built during the OpenAI 2026 hackathon as an integration of two prior systems (BadgeIn and Skybridge), with a focus on demonstrating how to enforce human approval for AI actions in a secure, auditable way.

Single most important open question

Is there any evidence that this system has moved beyond a proof-of-concept or demo into real-world usage or production integrations?

Back to contents

What The Product Actually Is

The description states that BadgeIn x Skybridge is a system composed of two components:

  • BadgeIn: A human approval interface that shows the exact app, action, resource, destination, payload digest, expiry, and invocation count. It allows denial or one-time approval.
  • Skybridge: A runtime enforcement layer that checks for valid, single-use grants before allowing actions to proceed.

The system uses:

  • Python-based authority service
  • Static HTML/CSS/JavaScript interface
  • HMAC-authenticated exact grants with atomic one-use consumption
  • Session-sandbox executor
  • Cloudflare Tunnel for HTTPS demo access
  • Qwen LLMs as fallbacks in a redundancy ladder

Inference: The product is described as a security-focused tool to prevent unauthorized AI actions by enforcing human authority at runtime.

Back to contents

Positioning & Claim Evolution

The description states:

  • AI agents are moving into business systems (calendars, files, inboxes).
  • The weak point is not model accuracy but authority.
  • Prompt injection succeeds when language can impersonate permission.
  • The system assumes a model may be fooled and prevents that mistake from becoming an action.

Claim: "TFB BadgeIn × Skybridge moves authority outside language."

This positions the product as a solution to prompt injection, not just AI accuracy or control.

Inference: The positioning is rooted in security and trust, not general-purpose AI orchestration or productivity tools.

Back to contents

Target Customer & ICP

The description does not name specific customers or target industries.

It implies use cases in business systems where AI agents interact with sensitive data or actions (e.g., calendars, files, inboxes).

Inference: The system is likely aimed at enterprises or developers who manage AI agents in production and want to enforce human oversight for security-sensitive operations.

Back to contents

Business Model & Pricing Evidence

No evidence of pricing, monetization, or business model is provided.

The description focuses on the technical architecture and demo execution, not commercial viability.

Not evidenced

Back to contents

Technical & Delivery Signals

The system is built with:

  • Python
  • HTML/CSS/JavaScript
  • Cloudflare Tunnel
  • Qwen LLMs (local fallbacks)
  • HMAC-authenticated grants
  • Session sandboxed executor
  • Pytest and adversarial test harnesses

It includes:

  • Deterministic app manifests
  • Same-origin human approval
  • Hash-chained authority history
  • Route failure narration (e.g., showing which fallback answered)

Inference: The system is built with a focus on security, determinism, and auditability. It uses local LLMs and sandboxed execution to reduce reliance on external APIs.

Back to contents

Traction & Maturity Signals

The description states:

  • A demo was built during a hackathon (OpenAI 2026)
  • The system passed 71 tests and 42 stress case groups
  • It retained 0 unauthorized executions, detected all 3 evidence-tamper cases, preserved 3 authorized positive controls
  • One winner among 48 concurrent attempts was allowed to spend a single-use grant

Not evidenced: No real-world usage, customers, revenue, or adoption data.

Back to contents

Competitive Context

The description does not name competitors or reference existing tools in the market.

It positions itself as solving prompt injection and AI action control, which is a niche but emerging area of concern.

Inference: The product may be addressing a gap in AI governance and security, particularly around human-in-the-loop controls for AI agents.

Back to contents

Key Risks & Red Flags

  • Demo-only: No evidence of production use or real-world integration.
  • No commercial traction: No revenue, customers, or adoption data.
  • Self-reported only: All claims are unverified.
  • Limited team size: Only one member (Saul Lowery) is listed.
  • Hackathon origin: The system was built in a short time for a contest, not as a long-term product.

Back to contents

Diligence Questions To Ask The Founders

  1. What real-world use cases have you identified for this system beyond the demo?
  2. Have you tested this with any external AI agents or systems in production?
  3. How do you plan to scale human approval in high-throughput environments?
  4. Are there any known limitations of the current sandboxed execution model?
  5. What is your roadmap for moving from a hackathon demo to a production-ready product?

Back to contents

Investment/Partnership Verdict

Not evidenced

The description provides no evidence of traction, revenue, customers, or commercial viability. It is a self-reported hackathon project with no indication of real-world adoption or market readiness.

This system appears to be an experimental proof-of-concept in AI security and human authority enforcement. The author states it was built for a contest and not as a product, and there is no evidence that it has moved beyond that stage.

Confidence: Low. The entire analysis is based on self-reported claims with no external validation or data to support commercial viability.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.