A genuinely implemented WAF with real anomaly detection and a well-guarded AI investigation agent that meets the Defence brief in code, but the absent degraded-scenario demo and complete lack of visual deliverables leave its usability and design unproven.
The WAF-plus-LLM-triage combination is known, but the execution fills a real gap concretely: five named detectors with thresholds, warmup baselines and cooldowns, and an investigation agent restricted to read-only tools that must cite request IDs and mark assessments inconclusive when evidence is empty. C's 'incremental dashboard' reading understates how specific the failure modes are.
Members disagree here: scores range by 2.0 points.This is unambiguously security and resilience work: CRS prevention with per-service policies, earlier detection on a 15-second cycle including an upstream-error detector for failing services, and consequence reduction through investigations and evidence snapshots that survive log pruning. The evidence supports A and B over C's 'generic monitoring tool' reading.
Members disagree here: scores range by 3.0 points.It deploys as a single Go binary with embedded frontend and SQLite, keeps recording detections with no AI key (chat returns 503), and tolerates GeoIP download failure, with acknowledge/resolve/dismiss workflows and SSE progress. C's impracticality claim is overstated by the evidence, though tuning multi-service policies, paranoia levels and anomaly settings is genuinely non-trivial.
Members disagree here: scores range by 2.0 points.The code promises a coherent Nuxt 4 and Tailwind interface with ECharts, EN/PL i18n and severity badges, but zero screenshots, demo captures or deck exist, so visual quality is judged from framework choices alone.
16,277 lines by 3 authors with all 37 commits inside the event window, 27 test files with 66 cases including a gated live AI test, real Coraza rule compilation, SQLite-backed detection and investigation plumbing with crash recovery, and a 6,000-log seed generator. A working prototype, not a mock.
claude:glm-5.3-flash72.090% agreedots-studio/dots-3-note-preview:free74.0100% agreeinclusionai/ling-3.0-flash-sante:free57.050% agreeclaude:glm-5.3–judgeThe council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.