OpenAI 2026 hackathon

Linmas: Defensive Security Skills for AI Agents

Linmas uses Codex to turn one explicit software change into normalized security findings, a deterministic policy decision, and a portable Review Capsule, with human review required.

Solo project by Tan Kim Gwan · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,015 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

Linmas is an open-source, Codex-first defensive security review system for AI-assisted software development. The author describes it as a tool that uses AI agents (specifically Codex) to perform bounded, deterministic security reviews of code changes and generate portable "Review Capsules" containing normalized findings, policy decisions, and evidence. Human review remains required.

What changed

The project evolved from a collection of defensive skill instructions into a structured, proof-carrying review workflow during OpenAI Build Week. It now includes explicit workflows for eleven security skills, deterministic policy evaluation, offline demo capability, and portable Proof Chain bundles.

Single most important open question

Is there evidence that Linmas has been adopted or used beyond the author's own demonstrations? The description states no revenue, customers, or traction data are available beyond self-reported claims.

Back to contents

What The Product Actually Is

The description states that Linmas is an open-source, Codex-first defensive security review system for AI-assisted software development. It combines eleven focused security skills with a structured workflow and deterministic policy decisions.

It generates Review Capsules, which are portable bundles tied to the exact input (SHA-256 digest and byte length), containing:

  • Normalized security findings
  • Deterministic policy results
  • Evidence of execution
  • Human review requirement

The system is designed to be run locally or through Codex CLI, with no automatic approval or remediation. It supports offline execution and includes a reproducible judge demo.

Inference The product appears to be a tool for developers using AI coding agents to perform early-stage security checks on code changes before human review.

Back to contents

Positioning & Claim Evolution

The author states that Linmas is inspired by Indonesia’s community protection concept, Perlindungan Masyarakat, and aims to fill a gap in AI-assisted development where security reviews are inconsistent or missing. It positions itself as a first layer of defense for AI-assisted software.

It is not described as:

  • A penetration-testing toolkit
  • An exploit automation platform
  • A system that automatically approves code

Instead, it emphasizes:

  • Evidence-based review
  • Deterministic policy evaluation
  • Human review boundary
  • Portable and inspectable results

The project evolved from a collection of prompts into a structured workflow during OpenAI Build Week. The author notes that the tool is not meant to create false confidence, but rather to distinguish evidence from assumption.

Inference Linmas positions itself as a defensive, accountable, and transparent security assistant, not an autonomous remediation tool.

Back to contents

Target Customer & ICP

The description states that Linmas targets:

  • Solo developers
  • Small teams
  • AI-assisted software development environments

It is described as being useful for:

  • Early-stage risk identification
  • Collecting evidence
  • Understanding remediation
  • Bringing better information to human decision-makers

There is no mention of enterprise customers, specific industries, or use cases beyond general AI-assisted development.

Inference The ICP appears to be developers and small engineering teams using AI coding agents, with a focus on improving security review workflows in early-stage development.

Back to contents

Business Model & Pricing Evidence

The description states that Linmas is open source. No pricing or monetization model is mentioned. There is no evidence of revenue, subscriptions, or paid features.

Inference The business model appears to be open source with no direct commercial revenue, though the author may seek public review channels for plugin discovery and adoption.

Back to contents

Technical & Delivery Signals

The project was built using:

  • Node.js 24
  • ES modules
  • Markdown-based Agent Skills
  • JSON Schema
  • Codex CLI integration
  • GitHub Actions

It supports:

  • Namespaced, installable security skills
  • Deterministic policy packs
  • Offline before/after comparison
  • Portable Proof Chain bundles
  • Human review gate

The author notes that the demo requires no provider credentials or network access.

Inference The technical stack is developer-focused, with a strong emphasis on reproducibility, offline capability, and integration with AI agents like Codex.

Back to contents

Traction & Maturity Signals

The description states:

  • It was independently developed
  • It was submitted to the OpenAI 2026 hackathon
  • A real-world incident response case was used for testing
  • The author conducted a bounded live test using Codex CLI and gpt-5.6-sol model

However, no evidence of revenue, customers, or adoption beyond the author’s own use is provided.

Inference The project shows early maturity with a working demo and real-world application, but lacks measurable traction or market validation.

Back to contents

Competitive Context

The description does not mention specific competitors. However, it makes clear distinctions from:

  • Penetration-testing tools
  • Exploit automation platforms
  • Systems that auto-approve code

It is positioned as a defensive assistant rather than an autonomous security system.

Inference Linmas operates in a niche space of AI-assisted security review, where the key differentiator is evidence-carrying, human-reviewed workflows. No direct competitors are named or described.

Back to contents

Key Risks & Red Flags

  • No revenue or customer data: The project has no demonstrated commercial traction.
  • Self-reported only: All claims are unverified and based on the author’s own description.
  • Limited adoption: No evidence of use beyond the author’s own demos or incident response case.
  • Open-source model: While open source can attract users, it does not indicate commercial viability or scalability.
  • No third-party validation: No independent review or testing is mentioned.

Inference The project is early-stage, with no clear path to monetization or market adoption. It may be a proof-of-concept rather than a scalable product.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual scope of the real-world incident response case? Was it used in production, and how was it validated?
  2. Has Linmas been tested with other AI agents beyond Codex?
  3. Are there any plans or early feedback from developers using this tool outside of the author’s own use?
  4. How does Linmas handle edge cases or ambiguous inputs that may not fit into its defined security skills?
  5. What is the long-term vision for monetization, if any, given its open-source nature?

Back to contents

Investment/Partnership Verdict

Not evidenced: There is no evidence of revenue, customers, or traction to support an investment or partnership decision.

The project is described as open source, self-developed, and not affiliated with any institution. It shows early maturity with a working demo and real-world application, but lacks commercial validation or adoption beyond the author’s own use.

Inference This is a concept-stage product with potential for future development, but not yet ready for investment or partnership consideration without further evidence of traction or scalability.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.