OpenAI 2026 hackathon

One Step Wrong

A flight simulator for digital judgment: students make unmarked choices in realistic tasks, face delayed consequences, recover, and transfer what they learned.

Solo project by PengYue Peng · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,675 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be: One Step Wrong is a self-reported educational tool for digital judgment training, built as a hackathon project. It simulates realistic security scenarios where users make unmarked decisions and face delayed consequences, with adaptive AI used to enhance realism while deterministic code governs high-impact outcomes.

What changed: The product was developed during a Build Week hackathon and includes three reviewed rehearsals (Voice You Know, Sharing Scope, Recovery Window) that support behavior-derived endings, causal debriefing, and transfer probes. It uses GPT-5.6 for bounded adaptive tasks but does not allow the model to control high-impact state.

Single most important open question: Does this product have any evidence of traction, revenue, or customer adoption beyond the author’s own account?

Back to contents

What The Product Actually Is

The description states that One Step Wrong is a flight simulator for digital judgment. It includes three reviewed rehearsals in a deliberate learning path:

  • The Voice You Know explores independent verification during a payment-change request.
  • Sharing Scope explores audience and permission scope when collaborating on documents.
  • Recovery Window separates task access from account-recovery authority.

Each rehearsal supports:

  • Multiple behavior-derived endings
  • A causal debrief
  • An Evidence Coach
  • A replay path
  • A transfer probe in a different context

Scenario Studio lets educators turn public guidance and teaching briefs into playable rehearsals. The complete reviewed path works without an API key.

The product uses:

  • Next.js 16, React 19, strict TypeScript
  • OpenAI Responses API (GPT-5.6)
  • Zod for schema validation
  • Playwright, Axe, Cloudflare Workers
  • A deterministic simulation engine to govern consequential decisions

Inference: The tool is designed for security education in university settings, with a focus on experiential learning and delayed consequence modeling.

Back to contents

Positioning & Claim Evolution

The author claims that One Step Wrong reverses traditional security training by revealing the right answer after learners feel pressure — instead of before. It aims to simulate real-world digital judgment under stress.

It positions itself as:

  • A flight simulator for digital judgment
  • A tool that allows students to make unmarked choices in realistic tasks
  • A system that supports recovery, causal debriefing, and transfer learning

Inference: The positioning is rooted in experiential learning theory and aims to improve retention through delayed consequence modeling. It does not claim to be a commercial product or have any revenue-generating model.

Back to contents

Target Customer & ICP

The description states that the tool is intended for university security education, with educators using Scenario Studio to create rehearsals from public guidance and teaching briefs.

It mentions:

  • Twenty undergraduate students tested the system
  • All 20 said it was valuable for university security education
  • 95% reported learning something new

Inference: The primary user is likely an educator or instructional designer in higher education, targeting students in cybersecurity or digital safety curricula. No evidence of institutional adoption or commercial customer base.

Back to contents

Business Model & Pricing Evidence

The description does not state any business model or pricing structure.

It mentions:

  • No learner accounts
  • No analytics
  • No database
  • No real campus-service side effects

Inference: There is no indication that the product has a monetization strategy, customer base, or revenue model. The project appears to be a prototype or proof-of-concept.

Back to contents

Technical & Delivery Signals

The product was built with:

  • Next.js 16, React 19, TypeScript
  • OpenAI Responses API (GPT-5.6)
  • Zod for schema validation
  • Playwright, Axe, Cloudflare Workers
  • Deterministic simulation engine to govern state

Key technical features include:

  • Bounded adaptive tasks powered by GPT-5.6
  • Schema and cross-reference validation before model use
  • A deterministic engine that prevents model control of high-impact state
  • 151 schema, API, state, and component tests plus 23 browser tests
  • Responsive design for desktop and mobile (390 px width)

Inference: The architecture is designed to balance AI-driven realism with deterministic control over critical outcomes. It shows strong engineering discipline but lacks evidence of production deployment or scalability.

Back to contents

Traction & Maturity Signals

The only traction mentioned is:

  • Twenty undergraduate students tested the system
  • All 20 said it was valuable for university security education
  • 95% reported learning something new

This is described as a formative user test from a small convenience sample.

No evidence of:

  • Revenue
  • Customers
  • Product adoption
  • Market traction
  • Institutional partnerships or pilot programs

Inference: The product has no demonstrated traction beyond the author’s own testing. It remains in early-stage development and lacks any commercial or institutional validation.

Back to contents

Competitive Context

The description does not mention competitors or similar products.

It is a self-reported hackathon project, built for a specific educational use case (security training), with no indication of market positioning or competitive analysis.

Inference: No evidence of competitive landscape or prior art. The product appears to be unique in its approach but lacks any market validation or benchmarking.

Back to contents

Key Risks & Red Flags

  • No commercial traction or revenue model: The project is a prototype, not a product with a customer base.
  • Self-reported user testing only: The formative test involved only 20 students and was not controlled or peer-reviewed.
  • Unverified claims: All statements are self-reported and unverified.
  • No production deployment or scalability evidence: The tool is described as built for a hackathon, with no indication of long-term infrastructure or growth plans.
  • Limited scope: Only three rehearsals are included, with no indication of expansion or roadmap.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the intended market beyond university security education?
  2. Are there any pilot programs or partnerships with institutions already in progress?
  3. How does the deterministic engine handle edge cases not covered by schema validation?
  4. Is there a plan to monetize or scale this product beyond the hackathon prototype?
  5. What are the limitations of GPT-5.6 in this context, and how are they mitigated?
  6. Are there any plans for additional reviewed judgment patterns or scenario types?

Back to contents

Investment/Partnership Verdict

Not evidenced: There is no evidence of revenue, customers, traction, or institutional adoption.

The project is a self-reported hackathon prototype, built with strong technical discipline but without any commercial or market validation. It is not currently a viable investment or partnership opportunity based on the information provided.

Confidence level: Low — this analysis is based entirely on self-reported claims and lacks any independent verification or evidence of traction, customers, or revenue.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.