Artificial IntelligenceSelf-submittedNot a finalist (self-declared)

OpenWAF

OpenWAF-Team · AleksanderGPL/OpenWAF

Council score

Median of 3 models, weighted by the task's official criteria
78.0 / 100

A genuinely engineered agentic security-triage layer on a working WAF, built entirely during the event with real guardrails and tests, whose entry is capped by missing visual, demo and submission-form deliverables rather than by what was built.

Criteria · line = median, dots = each member
Idea & Innovation30%
8.0

Unanimous. This is more than a chat wrapper: bounded autonomous investigations, read-only telemetry tools, and report validation that rejects evidence citations not returned by tools. Docked because commercial AI SOC triage already exists and the detection layer feeding it is fixed-threshold heuristics.

Relation to Category20%
8.5

The AI layer is the headline feature, wired into detection, SSE progress and the operator workflow. The council sides with A and B over C here: strip the model and a working Coraza/CRS WAF with dashboard remains, so AI is the differentiating layer rather than the entire product.

Practical Applicability / Usability20%
8.0

A concrete user is served end to end: cited request IDs, evidence snapshots, acknowledge/resolve/dismiss, retry and cancel, adjustable thresholds, and read-only tools that cannot touch WAF rules. Docked because no screenshot or demo lets the jury confirm the actual UI, and setup needs AI_KEY and AI_MODEL.

Design (visual/UI)20%
6.0

The codebase shows a real Nuxt frontend with Tailwind, EN/PL i18n, ECharts and a coherent admin layout, which supports B's mid score over A's 4 and C's 7. But with zero screenshots, no deck and no demo text, the rendered UI is inferred from code alone and cannot be verified.

Members disagree here: scores range by 3.0 points.
Completeness & Implementation Value10%
9.0

16,277 LOC across 37 commits, all during the event with none before or after, 66 test cases in 27 files, real integrations and guardrails with explicit failure states. The median keeps A's caveat in view but the code and test suite carry the score: the live AI test exists yet is opt-in and gated on a key, with no recorded run in the pack.

Source lines16,277
Tests66 cases
Claims built8.0 / 10
Task fitYes

Strengths

  • Real tool-calling agent over live telemetry with bounded iterations, tool calls, concurrency and deadlines, not a canned model response.
  • Evidence discipline: cited request IDs are validated against tool results, snapshots are retained, and missing evidence forces an inconclusive assessment.
  • Strong operator control: acknowledge, resolve, dismiss, retry and cancel, per-service thresholds, SSE with replay, and read-only tools that cannot change WAF rules or block traffic.
  • Substantial event-built implementation with honest documentation, including limits, failure states and open disclosure of the AI stack in the repo docs.

Weaknesses

  • No screenshots, demo video or deck, so visual design and UI usability cannot be judged from the submission pack.
  • The official submission form was left blank and only a repo link was shared, leaving required narrative deliverables missing.
  • Nothing in the pack shows the AI path executing end to end: the live investigation test is opt-in and gated on AI_KEY, so the jury cannot verify it without a key.
  • Detection feeding the AI is fixed-threshold heuristics and investigation quality depends on the chosen model, with no benchmark shown.
Built during the event: yes: 37 commits by 3 authors, 2026-10-03 10:35 to 2026-10-04 07:25 UTC
Live demo: none found in the form or README
Council v9
Aclaude:glm-5.3-flash70.070% agree
Bdots-studio/dots-3-note-preview:free78.0100% agree
Cinclusionai/ling-3.0-flash-sante:free81.080% agree
Jclaude:glm-5.3–judge
Self-submitted and unverified: the result shown is the team's own claim. The council read an evidence pack built from the repo, its decks and docs; it didn't run the code or see the pitch.
The site is open source

The council, the evidence pack, the prompts and the queue are all on GitHub. If a review helped you, a star helps other teams find it.

Star on GitHub