Skip to Main Content

Trojan PR

Built at The Agent Arena Hackathon · Sep 26, 2026 · San Francisco, CA

Trojan PR — Demo video

I've merged more than 140 fixes into ML libraries like DeepSpeed, Unsloth and sentence-transformers, and about two-thirds were silent math bugs: no crash, CI green, approved by human and AI reviewers, and a wrong number for months or years. One DeepSpeed bug returned 53 instead of 9 for 933 days. Trojan PR is the missing layer in PR review: it checks the math, not the diff. A model on Vultr Serverless Inference reads each PR and picks math rules (invariants) the code must obey, and the rules differ per PR. Those rules run in gVisor sandboxes on a separate Vultr VM, on the code before and after the PR. A deterministic judge blocks only if a rule held before and breaks on the PR, and signs an ed25519 receipt. On 12 real bug-causing PRs it raised zero false alarms on the 12 fixes, while an AI reviewer flagged 1 to 2 correct fixes. Everything is served through NetBird with a PIN and zero open ports.

Team