I Built an AI Security Agent for the TrueForge Hackathon
Here's how GuardForge works — and how I built it.
Last week I participated in The Agent Harness Hackathon by WeMakeDevs, TrueFoundry, and Qodo. The challenge was to build a real AI agent using TrueForge — one that connects to real tools, runs code safely in sandboxes, and always asks a human before doing anything irreversible. Here is what I built.
⚠️ The Problem
AI agents that have direct access to your codebase are dangerous if left unchecked. They can merge broken code, run untested fixes, or deploy to production — all without asking anyone. Most agents are either too restricted to be useful, or too unrestricted to be safe.
🤖 What is GuardForge?
GuardForge is an autonomous DevOps and Code Security Agent built on TrueForge — TrueFoundry's open-source agent harness. It scans repositories for CVE vulnerabilities, patches and tests fixes inside isolated Daytona sandboxes, and enforces a Human-in-the-Loop safety gate before merging anything into production.
⚙️ How It Works — Step by Step
The TrueForge runtime reads the user's task and maps out which MCP tools to call.
Calls
mcp-security-scanner to audit dependencies. Finds CVE-2026-3104 in lodash@4.17.15.A subagent spins up an isolated container, upgrades the dependency, and runs 142 unit tests — all green ✅
TrueForge pauses the agent completely. A modal pops up on screen — the human must click Approve & Merge or Reject before anything happens.
Once approved, the Pull Request merges into main. Qodo audit trail logged. Deployment complete.
🛠️ Tech Stack
🔍 How Qodo Improved My Code
Every feature was built on a separate branch and reviewed by Qodo Merge automatically on each Pull Request. Qodo caught real bugs including:
- A missing edge case in the
/api/approvalendpoint that would crash if no approval was pending - Silent failures in
fetch()calls with notry/catcherror handling - An infinite WebSocket reconnect loop with no termination guard
🔗 Project Links
Built with ❤️ for the WeMakeDevs TrueForge Hackathon 2026
Comments
Post a Comment