WEMAKEDEVS × TRUEFOUNDRY HACKATHON 2026

I Built an AI Security Agent for the TrueForge Hackathon

Here's how GuardForge works — and how I built it.

Last week I participated in The Agent Harness Hackathon by WeMakeDevs, TrueFoundry, and Qodo. The challenge was to build a real AI agent using TrueForge — one that connects to real tools, runs code safely in sandboxes, and always asks a human before doing anything irreversible. Here is what I built.

⚠️ The Problem

AI agents that have direct access to your codebase are dangerous if left unchecked. They can merge broken code, run untested fixes, or deploy to production — all without asking anyone. Most agents are either too restricted to be useful, or too unrestricted to be safe.

🤖 What is GuardForge?

GuardForge is an autonomous DevOps and Code Security Agent built on TrueForge — TrueFoundry's open-source agent harness. It scans repositories for CVE vulnerabilities, patches and tests fixes inside isolated Daytona sandboxes, and enforces a Human-in-the-Loop safety gate before merging anything into production.

⚙️ How It Works — Step by Step

Step 1
Agent Perception & Planning
The TrueForge runtime reads the user's task and maps out which MCP tools to call.
Step 2
MCP Security Scanner
Calls mcp-security-scanner to audit dependencies. Finds CVE-2026-3104 in lodash@4.17.15.
Step 3
Daytona Sandbox Execution
A subagent spins up an isolated container, upgrades the dependency, and runs 142 unit tests — all green ✅
Step 4 ⚠️
Human-in-the-Loop Safety Gate
TrueForge pauses the agent completely. A modal pops up on screen — the human must click Approve & Merge or Reject before anything happens.
Step 5
PR Merged & Incident Closed
Once approved, the Pull Request merges into main. Qodo audit trail logged. Deployment complete.

🛠️ Tech Stack

TrueForge MCP Tools Daytona Sandbox Node.js + Express WebSockets HTML / CSS / JS Qodo Merge

🔍 How Qodo Improved My Code

Every feature was built on a separate branch and reviewed by Qodo Merge automatically on each Pull Request. Qodo caught real bugs including:

  • A missing edge case in the /api/approval endpoint that would crash if no approval was pending
  • Silent failures in fetch() calls with no try/catch error handling
  • An infinite WebSocket reconnect loop with no termination guard

Built with ❤️ for the WeMakeDevs TrueForge Hackathon 2026

Comments