Cover Image for AI Security Engineering Hackathon
Cover Image for AI Security Engineering Hackathon
390 Went
Registration
Past Event
Please click on the button below to join the waitlist. You will be notified if additional spots become available.
About Event

​AI is moving faster than most security programs can keep up with — agentic tools, MCP servers, and AI-generated code are shipping into production every day, often outrunning the guardrails meant to protect them. This hackathon brings developers and security practitioners together to get hands-on with the skills defining the new discipline of AI Security Engineering. Working in teams, participants will tackle real-world AI security challenges spanning securing MCP servers and agent skills against tool poisoning and supply-chain attacks, and hardening vibe-coded applications.

​Whether you're a developer curious about securing AI-powered apps or a security specialist looking to apply your skills to LLMs and agents, you'll leave with practical, portfolio-ready experience — and the kind of muscle memory that only comes from breaking (and fixing) real systems. No prior AI security experience required — just a builder's mindset and curiosity about where AI meets attack surface.

​Agenda

  • ​9:30am: Doors open + Networking

  • ​10:00 am - 10:30 am: Welcome + Agenda + Intros

  • ​10:30 am -11:30 am: Introduction to AI Security Engineering

  • ​11:30 am - 12:00 pm: Hackathon guidelines

  • ​12:00 -12:30 pm: Lunch

  • ​12:30 -1:30 pm: Hackathon

  • ​1:30 pm: Submission deadline

  • ​1:35 pm - 1:45: Judges evaluate submissions

  • ​1:45 pm: Winners announced + Presentation

  • ​2pm: Event ends

​Registration (IMPORTANT)

​Space is limited, please ensure you register both in Luma and on the following AWS URL http://events.builder.aws.com/d/vcz3j3 (required to enter the AWS building).
All guests must be 18+ and present a valid government-issued physical photo ID at check-in (digital IDs will not be accepted). Scooters and bikes are not permitted in any Amazon building with no on-site parking available.

​Sponsors

​​​​​Snyk

​Snyk is a developer-first cybersecurity platform that helps teams build fast without compromising on security. As developers rely heavily on AI to write code at unprecedented speeds, Snyk continuously scans and secures application code, open-source dependencies, containers, and cloud environments right within the developer’s workflow. For an AI hackathon, it matters because shipping code quickly with AI generators or autonomous agents also means shipping security risks at machine speed. Snyk acts as an intelligent security layer, catching vulnerabilities and automatically applying verified fixes in real time—allowing builders to ship ambitious AI projects safely and with complete confidence.
At this event you will learn:
1) Sign-up for free (no credit card required), how to import your code, and configure your AI coding tool
2) Free AI Security Engineer Foundations Certificate

​Prizes

​$10,000 in Anthropic credits, free stickers and cool swag from some of our sponsors upon completing some of the activities


​AI Security Engineering Hackathon: Rules & Guidelines

​1. Event Overview

​Welcome to the AI Security Engineering Hackathon! This event brings together developers, security practitioners, and builders to get hands-on experience securing AI-powered and agentic applications.

  • ​Date: Tuesday, September 29, 2026

  • ​Location: AWS Builder Loft, First Market Tower, 525 Market St Entrance, San Francisco, CA 94105

  • ​Event Hosts: AI Security Engineers - SF Bay Area, Javier Garza, AISecEng Community, Trisha Rajesh, and AWS Builder Loft

  • ​Quickstart videos:

​2. Event Schedule

  • ​9:30 AM: Doors Open & Networking

  • ​10:00 AM – 10:30 AM: Welcome, Agenda & Intros

  • ​10:30 AM – 11:30 AM: Introduction to AI Security Engineering

  • ​11:30 AM – 12:00 PM: Hackathon Guidelines & Team Formation

  • ​12:00 PM – 1:30 PM: Hackathon / Building Session (~90 minutes). Lunch will be available during this time

  • ​1:30 PM: Submission Deadline

  • ​1:35 PM – 1:45 PM: Judges Evaluate Submissions

  • ​1:45 PM: Winners Announced & Presentations

  • ​2:00 PM: Event Ends

​3. Team Structure & Participation

  • ​Participants may compete individually or in teams of up to 4 people.

  • ​All participants must be registered for the event via Luma and the AWS Builder Loft registration link.

​4. Challenge Scope & Objective

​Design and build an application that showcases the AI security engineering skills

​Key Focus Areas include:

  • ​OWASP Top 10 for LLM Applications

  • ​Hardening agentic systems and MCP servers against tool poisoning and supply-chain attacks

​5. Build objectives

​People will have approximately 90 minutes to build a working project that teaches people about AI security engineering in a fun and engaging way.

​Your project should include a game-like chat agent people can interact to learn about at least 2 of the following topics:

  • ​Prompt injection

  • ​Tool poisoning

  • ​Excessive agent permissions

  • ​Unauthorized tool use

  • ​Sensitive data leakage

  • ​MCP supply-chain risks

  • ​Insecure tool execution

  • ​Agent abuse or unexpected behavior

​Your project must include three things:

  1. ​It explains the concept in a clear, concise and engaging manner

  2. ​Interacts with the user to test the concept in a challenge interaction (Look for Lakera’s Gandalf in YouTube for an idea for prompt injection)

  3. ​Provides hints to the user so each of the topic challenges can be solved to avoid people getting discouraged or stuck (i.e. gives you hints to help you find the solution to keep the person engaged)

​6. Required Submission Deliverables

​All teams must submit two key deliverables by 1:30 PM PDT:

  1. ​Public GitHub Repository:

    • ​Must contain the complete, readable application source code.

    • ​Include a clear README.md explaining setup instructions, application architecture, and security features implemented.

  2. ​Snyk Security Scan

    • ​Teams must create a free Snyk account and run a code and open-source security scan on their project before submission. Note: You will need to enable Code scan on your Snyk organization on app.snyk.io > settings > Snyk Code > Enable > Save Changes

  • ​You can use the Snyk CLI, or integrate Snyk Studio with your Agentic tool (i.e. Claude Code) and ask it to run a code and open source security scan. Review the scan results and address security issues where possible to avoid losing points.

  • ​Judges will consider the overall quality and security of your code, including Snyk scan results.

  • ​Guild Workspace link

    • ​Create a Guild.ai account

    • ​Teams must share a link to the workspace they used to host their Guild agents

  • ​Demo Video (Playable URL):

    • ​Maximum length: 90sec max.

    • ​Video must explain:

      • ​What the application does.

      • ​Why people should use the application.

      • ​How AI security engineering principles were integrated.

    • ​Format: Must be provided as a playable URL (e.g., YouTube or Vimeo).

    • ​Note: Video platforms take time to process and ingest uploads, so please plan your submission time accordingly.

  • ​Complete the Project Submission Form

​Submission Guidelines Checklist (Make a Copy)

​7. Judging & Evaluation Process

​Step 1: Video Review & Shortlisting

​The panel of judges will review all submitted video demonstrations and select the top 5 applications based on project scope, utility, presentation, and AI security innovation.

​Step 2: Snyk Security Code Scan

​The top 5 shortlisted applications will undergo code scanning using Snyk Code Security tools through javiergarza-snyk/app-security-score

  • ​Penalty System: Any security vulnerabilities, hardcoded secrets, or code quality flaws detected by Snyk will result in point deductions.

​Scoring Rubric

  • ​Implementation (30%): Application works, implements goal described, engaging and useful UI.

  • ​Presentation & Video Quality (30%): Clear demonstration, engaging pitch, adherence to the 90s video limit.

  • ​Code security (20%): Code is secure as reported by a Snyk security scan (fewer vulnerabilities = higher score).

  • ​Uses Guild.ai  (20%): Practical value, problem-solving impact, and creativity of the application.

​Scoring Rubric AI - Security Engineering Hackathon

​8. General Rules & Conduct

  • ​All work submitted must be created during the hackathon period.

  • ​All code must be open-source and hosted in a public GitHub repository.

  • ​Participants must adhere to ethical security testing and responsible disclosure standards.

​9. Prizes & Awards

​Teams will compete for prizes, we will be sharing vouchers of $1,000 in Anthropic credits to winners, along with additional AI security certification opportunities for participants.

​We will also be giving out several $500 vouchers in Anthropic credits for winners of some of the fun activities we will be running during the event

Location
AWS Builder Loft
First Market Tower, 525 Market St Entrance, San Francisco, CA 94105, USA
390 Went