

AI Security Engineering Hackathon
AI is moving faster than most security programs can keep up with — agentic tools, MCP servers, and AI-generated code are shipping into production every day, often outrunning the guardrails meant to protect them. This hackathon brings developers and security practitioners together to get hands-on with the skills defining the new discipline of AI Security Engineering. Working in teams, participants will tackle real-world AI security challenges spanning securing MCP servers and agent skills against tool poisoning and supply-chain attacks, and hardening vibe-coded applications.
Whether you're a developer curious about securing AI-powered apps or a security specialist looking to apply your skills to LLMs and agents, you'll leave with practical, portfolio-ready experience — and the kind of muscle memory that only comes from breaking (and fixing) real systems. No prior AI security experience required — just a builder's mindset and curiosity about where AI meets attack surface.
Agenda
9:30am: Doors open + Networking
10:00 am - 10:30 am: Welcome + Agenda + Intros
10:30 am -11:30 am: Introduction to AI Security Engineering
11:30 am - 12:00 pm: Hackathon guidelines
12:00 -12:30 pm: Lunch
12:30 -1:30 pm: Hackathon
1:30 pm: Submission deadline
1:35 pm - 1:45: Judges evaluate submissions
1:45 pm: Winners announced + Presentation
2pm: Event ends
Registration (IMPORTANT)
Space is limited, please ensure you register both in Luma and on the following AWS URL http://events.builder.aws.com/d/vcz3j3 (required to enter the AWS building).
All guests must be 18+ and present a valid government-issued physical photo ID at check-in (digital IDs will not be accepted). Scooters and bikes are not permitted in any Amazon building with no on-site parking available.
Sponsors
Snyk
Snyk is a developer-first cybersecurity platform that helps teams build fast without compromising on security. As developers rely heavily on AI to write code at unprecedented speeds, Snyk continuously scans and secures application code, open-source dependencies, containers, and cloud environments right within the developer’s workflow. For an AI hackathon, it matters because shipping code quickly with AI generators or autonomous agents also means shipping security risks at machine speed. Snyk acts as an intelligent security layer, catching vulnerabilities and automatically applying verified fixes in real time—allowing builders to ship ambitious AI projects safely and with complete confidence.
At this event you will learn:
1) Sign-up for free (no credit card required), how to import your code, and configure your AI coding tool
2) Free AI Security Engineer Foundations Certificate
Prizes
$10,000 in Anthropic credits, free stickers and cool swag from some of our sponsors upon completing some of the activities
AI Security Engineering Hackathon: Rules & Guidelines
1. Event Overview
Welcome to the AI Security Engineering Hackathon! This event brings together developers, security practitioners, and builders to get hands-on experience securing AI-powered and agentic applications.
Date: Tuesday, September 29, 2026
Location: AWS Builder Loft, First Market Tower, 525 Market St Entrance, San Francisco, CA 94105
Event Hosts: AI Security Engineers - SF Bay Area, Javier Garza, AISecEng Community, Trisha Rajesh, and AWS Builder Loft
Quickstart videos:
2. Event Schedule
9:30 AM: Doors Open & Networking
10:00 AM – 10:30 AM: Welcome, Agenda & Intros
10:30 AM – 11:30 AM: Introduction to AI Security Engineering
11:30 AM – 12:00 PM: Hackathon Guidelines & Team Formation
12:00 PM – 1:30 PM: Hackathon / Building Session (~90 minutes). Lunch will be available during this time
1:30 PM: Submission Deadline
1:35 PM – 1:45 PM: Judges Evaluate Submissions
1:45 PM: Winners Announced & Presentations
2:00 PM: Event Ends
3. Team Structure & Participation
Participants may compete individually or in teams of up to 4 people.
All participants must be registered for the event via Luma and the AWS Builder Loft registration link.
4. Challenge Scope & Objective
Design and build an application that showcases the AI security engineering skills
Key Focus Areas include:
OWASP Top 10 for LLM Applications
Hardening agentic systems and MCP servers against tool poisoning and supply-chain attacks
5. Build objectives
People will have approximately 90 minutes to build a working project that teaches people about AI security engineering in a fun and engaging way.
Your project should include a game-like chat agent people can interact to learn about at least 2 of the following topics:
Prompt injection
Tool poisoning
Excessive agent permissions
Unauthorized tool use
Sensitive data leakage
MCP supply-chain risks
Insecure tool execution
Agent abuse or unexpected behavior
Your project must include three things:
It explains the concept in a clear, concise and engaging manner
Interacts with the user to test the concept in a challenge interaction (Look for Lakera’s Gandalf in YouTube for an idea for prompt injection)
Provides hints to the user so each of the topic challenges can be solved to avoid people getting discouraged or stuck (i.e. gives you hints to help you find the solution to keep the person engaged)
6. Required Submission Deliverables
All teams must submit two key deliverables by 1:30 PM PDT:
Public GitHub Repository:
Must contain the complete, readable application source code.
Include a clear README.md explaining setup instructions, application architecture, and security features implemented.
Snyk Security Scan
Teams must create a free Snyk account and run a code and open-source security scan on their project before submission. Note: You will need to enable Code scan on your Snyk organization on app.snyk.io > settings > Snyk Code > Enable > Save Changes
You can use the Snyk CLI, or integrate Snyk Studio with your Agentic tool (i.e. Claude Code) and ask it to run a code and open source security scan. Review the scan results and address security issues where possible to avoid losing points.
Judges will consider the overall quality and security of your code, including Snyk scan results.
Guild Workspace link
Create a Guild.ai account
Teams must share a link to the workspace they used to host their Guild agents
Demo Video (Playable URL):
Maximum length: 90sec max.
Video must explain:
What the application does.
Why people should use the application.
How AI security engineering principles were integrated.
Format: Must be provided as a playable URL (e.g., YouTube or Vimeo).
Note: Video platforms take time to process and ingest uploads, so please plan your submission time accordingly.
Complete the Project Submission Form
Submission Guidelines Checklist (Make a Copy)
7. Judging & Evaluation Process
Step 1: Video Review & Shortlisting
The panel of judges will review all submitted video demonstrations and select the top 5 applications based on project scope, utility, presentation, and AI security innovation.
Step 2: Snyk Security Code Scan
The top 5 shortlisted applications will undergo code scanning using Snyk Code Security tools through javiergarza-snyk/app-security-score
Penalty System: Any security vulnerabilities, hardcoded secrets, or code quality flaws detected by Snyk will result in point deductions.
Scoring Rubric
Implementation (30%): Application works, implements goal described, engaging and useful UI.
Presentation & Video Quality (30%): Clear demonstration, engaging pitch, adherence to the 90s video limit.
Code security (20%): Code is secure as reported by a Snyk security scan (fewer vulnerabilities = higher score).
Uses Guild.ai (20%): Practical value, problem-solving impact, and creativity of the application.
Scoring Rubric AI - Security Engineering Hackathon
8. General Rules & Conduct
All work submitted must be created during the hackathon period.
All code must be open-source and hosted in a public GitHub repository.
Participants must adhere to ethical security testing and responsible disclosure standards.
9. Prizes & Awards
Teams will compete for prizes, we will be sharing vouchers of $1,000 in Anthropic credits to winners, along with additional AI security certification opportunities for participants.
We will also be giving out several $500 vouchers in Anthropic credits for winners of some of the fun activities we will be running during the event