OpenAI 2026 hackathon

JAK Shield - The Execution Firewall for AI Agents

JAK Shield is an MCP-native execution firewall for AI agents, blocking unsafe tool calls, redacting sensitive data, enforcing approvals and using GPT-5.6 for deeper risk analysis.

Solo project by REETURAJ GOSWAMI · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #4,700 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

JAK Shield is described as an MCP-native execution firewall for AI agents. It is positioned as a local-first security layer that sits between an AI agent and its tools, evaluating tool calls before execution and making deterministic decisions (allow, redact, rewrite, requires_approval, block) based on a policy engine.

What changed

The project description indicates a shift from prompt-level safety to a hard execution boundary. It introduces a layered approach combining deterministic controls with optional semantic analysis via GPT-5.6 for risk assessment, while maintaining strict enforcement authority that cannot be overridden by AI decisions.

Single most important open question — the commercial due-diligence read

Is there any evidence of real-world usage or integration beyond early testing and hackathon submission? The description states the product is ready for "controlled early testing" but not production deployment, with no mention of customers, revenue, or adoption.

Back to contents

What The Product Actually Is

The description states that JAK Shield is a local-first, MCP-native execution firewall for AI agents. It operates between an AI agent and its tools, evaluating every protected tool call and returning one of five decisions: allow, redact, rewrite, requires_approval, or block.

It uses:

  • A deterministic policy engine as the final enforcement authority.
  • Optional integration with GPT-5.6 for semantic risk analysis (used only for advisory purposes).
  • Taint tracking to monitor untrusted information across multiple tool calls.
  • Role-based access control (RBAC) and exact-call, scoped, single-use authorisation tokens.
  • A Floodgate emergency lockdown feature that closes all non-read-only execution paths.
  • Cryptographically signed audit records.

It supports:

  • MCP over STDIO and Streamable HTTP
  • REST API
  • Next.js dashboard
  • Electron desktop app

The product is built as a TypeScript monorepo, with components including:

  • Policy engine
  • MCP server (STDIO & HTTP)
  • Fastify REST API
  • Human approval gateway
  • PII/redaction layer
  • Prompt-injection detection
  • Signed audit infrastructure
  • Protected connector operations

It integrates with Codex via an MCP configuration, routing external side effects through shield.proxy_tool_call and using shield.evaluate_tool_call for non-destructive evaluations.

Back to contents

Positioning & Claim Evolution

The description states that the project was inspired by the realization that prompt-level safety is insufficient when AI agents can perform real-world actions like sending emails, running terminal commands, accessing databases, deploying software, publishing content, and initiating payments.

It claims to address a fundamental security problem: the same model deciding what action to take should not be the final authority deciding whether that action is safe.

The positioning has evolved from:

  • A general AI agent safety tool →
  • A hard execution boundary between intention and real-world impact →
  • A deterministic policy engine with optional semantic analysis, where AI is advisory, not authoritative

It also claims to be a universal execution-security layer for autonomous agents, aiming to give developers freedom without unchecked authority.

Back to contents

Target Customer & ICP

The description does not explicitly name target customers or define an Ideal Customer Profile (ICP). However, it implies that the primary users are:

  • Developers building AI agents
  • Teams integrating AI with real-world tools and systems
  • Organizations using MCP-compatible AI frameworks such as Codex

It is positioned for developers who want to build powerful AI systems without giving those systems unchecked authority over real-world tools.

Back to contents

Business Model & Pricing Evidence

Not evidenced. The description does not contain any information about pricing, monetization strategy, or business model.

Back to contents

Technical & Delivery Signals

The project is built as a TypeScript monorepo using:

  • Fastify
  • Next.js
  • Electron
  • Docker
  • PostgreSQL
  • Prisma
  • Prometheus
  • Zod
  • Vitest
  • Turborepo

It uses:

  • MCP (Model Control Protocol) over STDIO and Streamable HTTP
  • REST API
  • GPT-5.6 via OpenAI Responses API for optional semantic analysis
  • Local pre-egress redaction before AI analysis
  • Taint tracking across tool calls
  • Signed audit trails

It includes:

  • A verification flow that tests MCP startup, tool discovery, evaluation, proxying, and destructive SQL blocking.
  • Reference integrations for additional agent frameworks.

Back to contents

Traction & Maturity Signals

Not evidenced. The description states:

  • JAK Shield is ready for controlled early testing, not unrestricted production deployment.
  • It was submitted to the OpenAI 2026 hackathon.
  • It has undergone:
    • Clean Windows virtual-machine acceptance
    • Code signing (planned)
    • Independent penetration test (planned)
    • Multi-tenant hardening (planned)

No revenue, customers, or adoption data are provided.

Back to contents

Competitive Context

Not evidenced. The description does not mention competitors or the competitive landscape.

Back to contents

Key Risks & Red Flags

  • No traction or commercial use: The product is described as ready for early testing but not production deployment.
  • Unverified AI integration: GPT-5.6 is used only for advisory purposes, but its actual performance and reliability in real-world scenarios are unknown.
  • Limited validation: No third-party penetration tests, no customer feedback, no live deployments.
  • Self-reported maturity: The team states it’s not ready for production use, which raises questions about readiness for enterprise adoption.
  • Single-founder team: Only one member listed (REETURAJ GOSWAMI), which may limit scalability or operational capacity.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific real-world integrations or use cases have been tested beyond the hackathon?
  2. How is the deterministic policy engine validated and audited for correctness?
  3. Has the team conducted any internal or external security testing (e.g., penetration tests)?
  4. Are there any early adopters or pilot customers using this in a controlled environment?
  5. What are the plans for scaling beyond the current monorepo architecture?
  6. How does JAK Shield handle edge cases where the deterministic engine and GPT-5.6 disagree?
  7. What is the roadmap for enterprise features, multi-tenancy, and hosted deployment?

Back to contents

Investment/Partnership Verdict

Not evidenced. The description does not provide any information on funding rounds, valuation, or investment history.

The project appears to be in an early-stage prototype or proof-of-concept phase, submitted to a hackathon. It shows technical depth and a clear understanding of AI agent security challenges but lacks evidence of traction, revenue, customers, or commercial viability.

Confidence level: Low — based entirely on self-reported claims with no external validation or data points.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.