OpenAI 2026 hackathon

Codex Guard

The kernel decides, Codex proposes. No prompt to talk your way past, risky actions get classified, human-approved once, and cryptographically receipted.

Solo project by Daniel LaForce · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #3,388 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Codex Guard is a self-reported security and access-control system for AI coding agents like Codex. It positions itself as a "kernel" that sits between an AI agent and consequential actions, classifying risks and enforcing decisions via a human approval flow. The system claims to offer cryptographic audit trails and prevent prompt-injection-style bypasses.

What changed

The project description indicates this was built during a hackathon (OpenAI 2026) over a short time frame (a "Build Week"). It is described as an extension of an existing "custodian-kernel" policy engine, with new components added specifically for Codex integration. The author states that the system was built using Codex itself.

The single most important open question

Is there any evidence of real-world usage or adoption beyond the author’s own development environment and demo script?

Back to contents

What The Product Actually Is

The description states that Codex Guard is a policy enforcement layer for AI coding agents. It includes:

  • A MCP server, which acts as an interface between Codex and the system.
  • A risk classifier, which evaluates proposed actions based on their actual content, not their labels.
  • An approval flow, where only humans can approve risky actions once.
  • A cryptographically chained receipt log, which records all decisions and is tamper-evident.
  • A Codex plugin that integrates the system into Codex workflows.

The system is described as being built using Codex itself, including for testing its own classifier.

Inference It appears to be a prototype or proof-of-concept tool designed to secure AI coding agents from unintended or dangerous actions. It does not appear to be a commercial product yet.

Back to contents

Positioning & Claim Evolution

The author states that the system was inspired by the need for a "firewall" rather than a prompt-based guardrail, because prompts can be bypassed by smart models. The positioning is:

  • Security-first: It enforces rules outside of the agent’s own reasoning.
  • Tamper-evident logging: Receipts are cryptographically chained and not readable by the agent itself.
  • Human-in-the-loop: Decisions are made by humans, not models, and are tied to specific actions.

Inference The positioning reflects a concern about AI agent autonomy and the risks of uncontrolled access in production environments. It is positioned as a tool for secure AI agent deployment, not general-purpose coding assistance.

Back to contents

Target Customer & ICP

The description does not name any customers or target accounts. However, it implies that the system is intended for:

  • Organizations using AI coding agents like Codex.
  • Teams managing access to production systems through AI tools.
  • Developers or operators who want to enforce strict controls over what AI agents can do.

Inference The ICP (Ideal Customer Profile) likely includes early-stage developers, security-conscious teams, or enterprises deploying AI agents in production. However, no evidence of actual customer engagement is provided.

Back to contents

Business Model & Pricing Evidence

There is no evidence of pricing, monetization, or business model in the description.

Inference The system appears to be a prototype or hackathon project and not yet commercialized.

Back to contents

Technical & Delivery Signals

The system is built with:

  • Tools: argparse, git, gpt-5.6, hmac-sha256, json-rpc, mcp, model-context-protocol, openai-codex, pytest, python, sqlite.
  • Architecture: MCP server, risk classifier, receipt chain, approval flow, and Codex plugin.
  • Testing: The system was tested by Codex against its own classifier to find vulnerabilities.

Inference The technical stack is consistent with a Python-based tooling project. It uses cryptographic primitives (e.g., HMAC-SHA256) and integrates with AI agent protocols (MCP, Codex). However, there is no evidence of production deployment or scalability beyond the demo environment.

Back to contents

Traction & Maturity Signals

The description states:

  • The system was built in a single week during a hackathon.
  • A demo script exists that can be run without credentials or network calls.
  • It includes a test suite, and bugs were found and fixed during the build process.
  • It has been tested against adversarial inputs and holds up.

Inference There is no evidence of traction, revenue, or customer adoption. The system appears to be in early prototype form with limited real-world usage.

Back to contents

Competitive Context

The description does not mention any competitors or similar tools. However, it implies a space where:

  • AI agents are used for production-level tasks.
  • There is a need for secure access control and audit trails.
  • The system is positioned to complement existing AI agent frameworks, such as OpenCode.

Inference It likely competes with or complements tools that manage AI agent behavior in secure environments, but no direct competitors are named.

Back to contents

Key Risks & Red Flags

  • No real-world usage: The system has not been deployed beyond a demo script.
  • Unproven scalability: It was built for a single use case (Codex) and may not scale to other agents.
  • Limited adoption evidence: No customers, users, or feedback are mentioned.
  • Prototype nature: Built in a hackathon, with no indication of long-term development or commercialization.

Inference The project is early-stage and lacks any commercial or operational traction. It is not yet ready for production use or investment consideration.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the current status of the "custodian-kernel" that this system builds on?
  2. Has the system been tested in environments beyond the demo script?
  3. Are there any plans to support other AI agents beyond Codex?
  4. How does the system handle edge cases or unexpected inputs not covered in testing?
  5. What is the roadmap for production deployment or commercialization?

Back to contents

Investment/Partnership Verdict

Not evidenced.

There is no evidence of revenue, customers, traction, or a clear path to monetization. The project appears to be an early-stage prototype built during a hackathon, with no indication of commercial viability or strategic value beyond its own demonstration.

Confidence Low This analysis is based entirely on self-reported information and lacks any external validation or evidence of real-world usage or impact.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.