OpenAI 2026 hackathon

hardno-engine

hardno-engine is a local guardrail runtime that blocks risky AI-agent actions before execution and records explainable local receipts. Name inspired by (https://pokemondb.net/ability/hadron-engine)

Solo project by Sajjad Nakhwa · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,177 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Company: hardno-engine

Self-reported basis: The entire analysis is based on a single project description submitted by the author to the OpenAI 2026 hackathon on Devpost. No external verification, revenue, customer data or traction evidence is available.

What it appears to be: A local runtime guardrail tool designed to block risky AI-agent actions before execution and record explainable receipts. It operates as a policy firewall for AI coding agents, using a Go binary with YAML policy layers and JSONL trace logging.

What changed: The author submitted this project as part of a hackathon, indicating an early-stage development effort. No prior version or evolution is described.

Single most important open question: Is there any evidence that this tool has been used in real-world developer environments or integrated into existing workflows?

Back to contents

What The Product Actually Is

The description states that hardno-engine is a local guardrail runtime that blocks risky AI-agent actions before execution and records explainable local receipts. It functions as a policy firewall for AI coding agents, particularly targeting tools like Codex.

It includes:

  • Project, user, and built-in YAML policy layers
  • First-match rule evaluation
  • JSONL traces with a SQLite index
  • Log, explain, and scoped allow commands
  • Deterministic prompt-injection heuristics
  • A dependency-free hook-protocol adapter

The tool is implemented as a single static Go binary with two frontends:

  • PATH shims
  • A JSON hook adapter

It was built using Codex and GPT-5.6, and the author claims to have used Codex for architecture decisions, implementation, debugging, CLI design, documentation, and release preparation.

Inference: The tool is a developer-facing utility designed to enforce safety policies in AI-assisted coding workflows, with an emphasis on local execution and traceability.

Back to contents

Positioning & Claim Evolution

The author states that the inspiration came from a desire to keep safety policy ownership with the developer and project, rather than with the agent itself. This suggests a positioning around developer autonomy and control over AI agent behavior.

The product is described as:

  • A local policy firewall
  • Designed to block dangerous actions before execution
  • To record explainable receipts

There is no evidence of prior versions, market positioning or competitor comparisons in the description.

Inference: The tool positions itself as a developer-centric safety layer, not a commercial product. It is a proof-of-concept or hackathon submission, not a mature product with a defined market.

Back to contents

Target Customer & ICP

The author describes hardno-engine as a local guardrail runtime for AI coding agents. The primary use case involves developers using tools like Codex, where the tool acts as a policy enforcement layer.

It is built to be used in developer environments, with support for:

  • PATH shims
  • JSON hook adapter

There is no mention of enterprise customers, specific developer personas, or segmentation beyond "developers using AI agents."

Inference: The target customer is likely individual developers or small teams working with AI coding tools. No evidence of a defined ICP (Ideal Customer Profile) exists.

Back to contents

Business Model & Pricing Evidence

The description does not contain any information about:

  • Revenue model
  • Pricing structure
  • Monetization strategy
  • Paid features or tiers

It is presented as a single static binary with no indication of commercial licensing, subscriptions, or paid access.

Inference: No business model or pricing evidence is provided. The tool appears to be an open-source or prototype effort.

Back to contents

Technical & Delivery Signals

The author states:

  • Built with Go, Codex, and GPT-5.6
  • Uses YAML policy layers, JSONL traces, and SQLite index
  • Implements a dependency-free hook-protocol adapter
  • Includes table-driven policy tests, scripted wrapped-shell sessions, golden JSON fixtures, race detection, and failure-mode tests

It is a single static binary with two frontends (PATH shims and JSON hook adapter).

Inference: The tool is technically well-thought-out for a prototype, with attention to testing, observability, and modularity. However, it is not yet a production-grade product.

Back to contents

Traction & Maturity Signals

The project is described as:

  • A hackathon submission
  • Released as v0.1.0
  • Built during Build Week
  • Repository: https://github.com/ndstab/hardno-engine
  • Release: https://github.com/ndstab/hardno-engine/releases/tag/v0.1.0

There is no evidence of:

  • Customers
  • Usage metrics
  • Adoption
  • Product-market fit
  • Revenue or funding

Inference: The tool is in a very early stage, likely a prototype or proof-of-concept, with no traction or maturity signals.

Back to contents

Competitive Context

The description does not mention any competitors or direct market context. It is not clear whether similar tools exist in the market for AI agent safety or policy enforcement.

Inference: No competitive landscape is described. The tool may be unique or early in a niche space, but this cannot be confirmed without external data.

Back to contents

Key Risks & Red Flags

  • No traction or adoption evidence: The project is presented as a hackathon submission with no real-world usage.
  • Unproven commercial viability: No business model, pricing, or monetization strategy is evident.
  • Single-person team: Only one developer is listed, which may limit scalability and product development velocity.
  • Prototype nature: The tool is described as v0.1.0, suggesting it is not yet mature for production use.
  • No external validation or testing: All evidence is self-reported.

Inference: The tool is a conceptual prototype, not a commercial product. It may be useful in early-stage experimentation but lacks any signs of real-world utility or scalability.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific AI coding agents does hardno-engine currently support, and how are they integrated?
  2. How is the policy enforcement boundary defined, and what are the known limitations of interception?
  3. Has the tool been tested in real-world developer workflows or environments?
  4. Are there any plans to expand beyond local execution or support for other platforms (e.g., Windows)?
  5. What is the intended path from prototype to commercial product, if any?

Back to contents

Investment/Partnership Verdict

Not evidenced: There is no evidence of a business model, revenue, customer traction, or commercial viability. The tool is described as a hackathon submission, not a product ready for investment or partnership.

The author states that the project was submitted to the OpenAI 2026 hackathon and includes no data on adoption, usage, or monetization.

Inference: This is an early-stage prototype, likely with potential for future development. However, it does not currently meet criteria for commercial due diligence or investment consideration.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.