Anvil
by Anvil
Two AI agents battle over a vulnerable Flask app in real-time. Red Agent finds and exploits security vulnerabilities. Blue Agent patches them. Watch it happen live in a dark-themed dashboard with streaming AI reasoning.
About This Project
Anvil is a live AI security battle where two AI agents go head-to-head over a vulnerable Flask app. A Red Agent finds and exploits real vulnerabilities (SQL injection, IDOR, etc.) while a Blue Agent patches them in real-time — all streamed to a dark-themed dashboard with live AI reasoning. Built with MiniMax M2.7-highspeed, the whole thing runs in 3 rounds with concurrent judging, automatic rollback on bad patches, and a post-battle security report.
- Red crafts real curl attacks, Blue rewrites the actual source code
- Everything runs live — streaming extended thinking, SSE events, subprocess restarts
- No frameworks on the frontend, no hand-holding on the AI — just two agents competing
Built With
Repository
Real-time AI security hardening pipeline. Automated red team/blue team loop that finds and patches vulnerabilities in your codebase.
Submitted March 19, 2026 at 8:22 PM