OpenAI 2026 hackathon

ToolBastion

A security gateway for MCP tool calls that validates tool identity and arguments, blocks risky actions before execution, inspects outputs, and preserves a tamper-evident audit trail.

Solo project by Muhammad Muavia Muavia · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #2,098 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Company: ToolBastion

Self-reported purpose: A security gateway for Model Context Protocol (MCP) tool calls that validates identity, blocks risky actions, inspects outputs, and preserves tamper-evident audit trails.

Key claim: To mediate MCP tool calls with deterministic enforcement, containment, and evidence.

What changed: The author built a TypeScript-based MCP proxy to enforce security policies before execution, using Zod validation, Docker containment, and structured GPT-5.6 checks for ambiguous cases.

Most important open question: Does ToolBastion have any real-world usage or integration with existing MCP agents or tools?

The description is self-reported and unverified. It states no revenue, customers, traction, or adoption data. The project appears to be a proof-of-concept or prototype built for a hackathon. No evidence of commercial viability, market demand, or product-market fit is provided.

Back to contents

What The Product Actually Is

  • The description states ToolBastion is implemented as a TypeScript MCP proxy.
  • It presents an MCP server to the agent and connects to one local stdio MCP target.
  • It includes:
    • Zod-validated configuration and protocol boundaries
    • Filesystem capability contracts with containment and symlink protection
    • URL, shell, Unicode, encoding, nesting, and output-injection detection
    • Trust baselines bound to Docker digests or executable/build/dependency hashes
    • Durable redacted receipts and tamper-evident audit chains
    • Optional Docker target-process containment with network isolation
    • Structured GPT-5.6 checks for ambiguous requests only
    • A read-only dashboard for runtime and recorded evidence
    • Property-based adversarial tests using fast-check
    • Unit, integration, Docker, Playwright, evaluation, packaging, and release checks

Inference: ToolBastion is a security middleware that sits between an AI coding agent and local MCP targets. It enforces deterministic policies before execution, logs actions, and provides evidence of what happened.

Back to contents

Positioning & Claim Evolution

  • The description states the author built ToolBastion to make each mediated tool call explainable: what was requested, what policy decided, whether the target executed, and what evidence was retained.
  • It is positioned as a security gateway for MCP tool calls.
  • The author claims:
    • Deterministic security controls must run before model judgment.
    • Trustworthy evidence requires binding to actual target artifacts (e.g., Docker digests).
    • GPT-5.6 should receive bounded, schema-validated context.
    • The recorded demo fixture resolves deterministically without GPT.

Inference: ToolBastion is positioned as a secure, auditable, and explainable layer for MCP-based AI agents, with emphasis on deterministic enforcement and evidence preservation.

Back to contents

Target Customer & ICP

  • Not evidenced.
  • The description does not state who the intended users or customers are.
  • No mention of existing or target markets, personas, or use cases beyond a hackathon project.

Back to contents

Business Model & Pricing Evidence

  • Not evidenced.
  • No information about pricing, monetization strategy, or business model is provided in the description.

Back to contents

Technical & Delivery Signals

  • Built with:
    • Developer tools: Docker, GitHub Actions, Fastify, React, TypeScript, Node.js, Vite, Zod, Playwright, Vitest, fast-check
    • Security features: Filesystem containment, symlink protection, URL/encoding detection, Docker digest binding, tamper-evident audit chains
    • MCP integration: Implements an MCP proxy server and connects to stdio MCP targets
  • The system includes:
    • Zod validation for configuration and protocol boundaries
    • Structured GPT-5.6 checks for ambiguous requests only
    • Read-only dashboard for evidence inspection
    • Property-based adversarial testing with fast-check
    • Multiple test layers: unit, integration, Docker, Playwright, evaluation, packaging, release

Inference: ToolBastion is a developer-focused security tool, built with modern TypeScript and Node.js stacks, with strong emphasis on testing, validation, and containment.

Back to contents

Traction & Maturity Signals

  • Not evidenced.
  • No evidence of revenue, customers, usage metrics, or adoption.
  • The project was submitted to the OpenAI 2026 hackathon, suggesting it is a prototype or proof-of-concept.
  • No mention of production use, integrations, or feedback from users.

Back to contents

Competitive Context

  • Not evidenced.
  • No information about competitors or existing solutions in the market for MCP security gateways.
  • The description does not reference similar tools or platforms.

Back to contents

Key Risks & Red Flags

  • Prototype nature: Built for a hackathon; no evidence of real-world usage or production deployment.
  • No commercial traction: No revenue, customers, or adoption data provided.
  • Single-founder project: Team size is listed as 1.
  • Unverified claims: The description makes strong technical and security claims but does not provide evidence of their implementation or effectiveness.
  • Unclear market fit: No indication of target customer segment or demand.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific MCP agents or tools are you planning to integrate ToolBastion with?
  2. Have you tested ToolBastion in real-world scenarios beyond the hackathon prototype?
  3. How does ToolBastion handle edge cases in cross-platform environments (e.g., Windows vs Linux)?
  4. Is there a plan for monetization or commercial deployment?
  5. What is your roadmap for scaling beyond the current prototype?

Back to contents

Investment/Partnership Verdict

  • Not evidenced.
  • The description provides no information about valuation, funding rounds, or investment interest.
  • ToolBastion appears to be a proof-of-concept built for a hackathon with no demonstrated traction or commercial viability.
  • It is not clear whether this project has moved beyond prototype stage or has any real-world application.

Confidence: Low. The description is self-reported and unverified, with no evidence of revenue, customers, or market traction.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.