OpenWAF-Team · AleksanderGPL/OpenWAF
A genuinely engineered agentic security-triage layer on a working WAF, built entirely during the event with real guardrails and tests, whose entry is capped by missing visual, demo and submission-form deliverables rather than by what was built.
Unanimous. This is more than a chat wrapper: bounded autonomous investigations, read-only telemetry tools, and report validation that rejects evidence citations not returned by tools. Docked because commercial AI SOC triage already exists and the detection layer feeding it is fixed-threshold heuristics.
The AI layer is the headline feature, wired into detection, SSE progress and the operator workflow. The council sides with A and B over C here: strip the model and a working Coraza/CRS WAF with dashboard remains, so AI is the differentiating layer rather than the entire product.
A concrete user is served end to end: cited request IDs, evidence snapshots, acknowledge/resolve/dismiss, retry and cancel, adjustable thresholds, and read-only tools that cannot touch WAF rules. Docked because no screenshot or demo lets the jury confirm the actual UI, and setup needs AI_KEY and AI_MODEL.
The codebase shows a real Nuxt frontend with Tailwind, EN/PL i18n, ECharts and a coherent admin layout, which supports B's mid score over A's 4 and C's 7. But with zero screenshots, no deck and no demo text, the rendered UI is inferred from code alone and cannot be verified.
Members disagree here: scores range by 3.0 points.16,277 LOC across 37 commits, all during the event with none before or after, 66 test cases in 27 files, real integrations and guardrails with explicit failure states. The median keeps A's caveat in view but the code and test suite carry the score: the live AI test exists yet is opt-in and gated on a key, with no recorded run in the pack.
claude:glm-5.3-flash70.070% agreedots-studio/dots-3-note-preview:free78.0100% agreeinclusionai/ling-3.0-flash-sante:free81.080% agreeclaude:glm-5.3–judgeThe council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.