OpenAI 2026 hackathon

Hedge

An evidence-linked security architecture diff for TypeScript pull requests: silent on benign changes, exact about meaningful ones.

Solo project by Caleb Todd · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #4,478 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Hedge is a self-reported security architecture diff tool for TypeScript pull requests, built as a GitHub Action and CLI. It analyzes changes in code structure and workflow to surface potential security risks related to attack surfaces, trust boundaries, controls, and privilege levels. The tool uses deterministic analysis where possible and integrates GPT-5.6 only after establishing architectural deltas.

What changed

The author, Caleb Todd, built Hedge during a hackathon (OpenAI 2026) with the goal of improving security review by focusing on architecture-level changes rather than line-by-line diffs. It was designed to avoid generic AI scanning and instead focus on supported attack-surface patterns in TypeScript-based web frameworks like Next.js and Express.

Single most important open question

Is there any evidence of real-world usage or integration beyond the author's own testing and demonstration? The description states that Hedge ships as a GitHub Action and CLI, but does not indicate whether it is used by teams or organizations outside of its creator’s repository.

Back to contents

What The Product Actually Is

The description states:

  • Hedge is an evidence-linked security architecture diff for TypeScript pull requests.
  • It compares base and head revisions to build an attack-surface graph and report architectural deltas.
  • It supports specific frameworks like Next.js App Router, Pages API routes, Express routes, and middleware.
  • It produces outputs including HTML diffs, Markdown reports, SARIF, JSON graphs, GitHub annotations, and proof bundles.

Inference Hedge appears to be a developer tool that integrates into CI/CD workflows via GitHub Actions and CLI. Its core functionality involves analyzing code structure for architectural risk, not line-level vulnerabilities or generic scanning.

Back to contents

Positioning & Claim Evolution

The description states:

  • Hedge is deliberately not a "generic AI security scanner."
  • It surfaces supported attack-surface changes and design risks, not vulnerabilities.
  • It does not claim to find or prove vulnerabilities.
  • The tool uses deterministic architecture analysis before involving AI models.

Inference Hedge positions itself as a precision-focused tool for architectural risk detection in code review, rather than a broad vulnerability scanner. It emphasizes accuracy over generality and separates model interpretation from final decision-making.

Back to contents

Target Customer & ICP

The description states:

  • Hedge targets developers working with TypeScript-based web frameworks (Next.js, Express).
  • It is designed to integrate into GitHub workflows for pull request security review.
  • The tool supports specific patterns such as route handlers, middleware matchers, and database/storage operations.

Inference Hedge likely targets engineering teams using modern JavaScript/TypeScript stacks who want to automate architecture-level security checks during code review. It is not positioned for general-purpose software development or non-web applications.

Back to contents

Business Model & Pricing Evidence

The description states:

  • Hedge ships as a Node 24 GitHub Action and Node 22 CLI with checksum-verified releases.
  • The repository includes installation diagnostics, test files, and verification workflows.
  • No pricing information or commercial model is mentioned.

Inference There is no evidence of a business model or pricing structure in the description. It appears to be an open-source or internal tool built for demonstration purposes.

Back to contents

Technical & Delivery Signals

The description states:

  • Hedge uses esbuild, GitHub Actions, Node.js, OpenAI Codex/GPT-5.6, TypeScript compiler API, Vitest, Zod.
  • It separates authority across jobs in the GitHub workflow (collector, reasoning, publisher).
  • It supports Next.js App Router, Pages API routes, Express routes, Prisma, object storage, outbound network, and more.
  • It produces interactive HTML diffs, Markdown, SARIF, JSON, GitHub annotations, and tamper-evident proof bundles.

Inference Hedge is technically sophisticated, leveraging both static analysis and AI for selective interpretation. Its modular architecture separates concerns and ensures trust boundaries in CI/CD pipelines.

Back to contents

Traction & Maturity Signals

The description states:

  • 259 unit, contract, replay, workflow, and schema tests pass across 53 test files.
  • All 47 bundled deterministic DriftBench cases pass.
  • Source-only smoke tests on one App Router, one Pages API, and one Express repository were silent on documentation-only changes and produced exact evidence for supported upload/storage changes.
  • A benign judge-lab pull request produced no Hedge comment and no model call.
  • A live architecture-changing pull request completed full collect -> reason -> publish path, rejected one unsupported model proposal, cited exact evidence, and recorded a BLOCK decision.
  • One remote verification run passed all four requirements and recorded HEDGE-009 as verified through a reviewable state pull request.

Inference Hedge has demonstrated functionality in controlled environments and shows maturity in deterministic behavior. However, there is no evidence of real-world adoption or usage beyond the author’s own testing.

Back to contents

Competitive Context

The description states:

  • Hedge is deliberately not a generic AI security scanner.
  • It focuses on supported attack-surface patterns rather than broad vulnerability detection.
  • No mention of competitors or market positioning beyond its own design choices.

Inference Hedge operates in a niche space focused on architecture-level change analysis, distinct from general-purpose tools like Snyk, SonarQube, or GitHub Advanced Security. It may compete with specialized tools for secure code review but lacks evidence of direct competition.

Back to contents

Key Risks & Red Flags

The description states:

  • Model reliability and automatic remediation publication remain next-release work.
  • One frozen ten-case model evaluation showed only two cases with stable exact finding/decision signatures.
  • A draft patch was labeled experimental due to a pre-existing empty Vitest suite.
  • The tool is built by one person (Caleb Todd) and has no external validation or traction.

Inference Key risks include incomplete automation, limited model reliability, and lack of real-world usage. The project remains in early development and lacks evidence of scalability or commercial viability.

Back to contents

Diligence Questions To Ask The Founders

  1. Has Hedge been integrated into any production environments or CI/CD pipelines beyond the author’s own testing?
  2. What is the current status of model reliability and remediation automation? Are there plans to address known limitations?
  3. How does Hedge handle edge cases or unsupported frameworks, and what is the roadmap for expanding coverage?
  4. Is there a plan to monetize or commercialize Hedge, or is it intended as an open-source tool?
  5. What are the long-term maintenance and support plans for the project?

Back to contents

Investment/Partnership Verdict

The description states:

  • Hedge is a proof-of-concept built during a hackathon by one engineer (Caleb Todd).
  • It demonstrates technical capability in deterministic architecture diffing and AI integration.
  • There is no evidence of revenue, customers, or traction beyond author’s own testing.

Inference Hedge is an early-stage prototype with strong technical execution but lacks commercial viability or adoption signals. It may be suitable for incubation or strategic partnership if further development addresses model reliability and automation gaps. However, it is not ready for investment or large-scale deployment without significant additional work.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.