Qwen Cloud hackathon submission workspace.
AegisOps is a Track 4 Autopilot Agent safety harness, not a passive incident dashboard. Qwen Cloud plans through five external tools, the same tool surface is exposed through OpenAPI and MCP for judge verification, and a human approval gate blocks risky mutations before they touch production.
The ablation evidence is front-loaded for judging: the full workflow scores 0.988 versus 0.420 for the single-agent baseline in reports/ablation_report.md. The stress benchmark expands this across 14 production-style incident scenarios, 14 services, 70 approved-path tool calls, and 14/14 blocked-mutation checks in reports/stress_benchmark.md. The adversarial authority benchmark adds 56 corrupted model/tool-boundary attacks with 56/56 authority-boundary checks passed, 14/14 active-incident scoping checks, 14/14 approval-bypass blocks, 14/14 unknown-tool rejections, and 14/14 policy hard-stop checks in reports/adversarial_authority_benchmark.md. A one-shot live Qwen smoke proof is verified in reports/live_qwen_smoke_proof.md: qwen-plus, Qwen Cloud mode, five tool schemas, and no saved secret. The gain comes from memory, tool-backed evidence, policy checks, dry-run remediation, and approval gating rather than a single free-form agent response.
The implementation is designed for two judging modes:
- Live Qwen mode: set
DASHSCOPE_API_KEYorQWEN_API_KEYand the server calls Qwen Cloud through the OpenAI-compatible endpoint, including a capped Function Calling loop for incident tools. - Offline demo mode: no secret is required; deterministic fixtures exercise the same orchestration path for judges and CI.
pnpm install
pnpm run test
pnpm run build
pnpm run eval
pnpm run eval:ablation
pnpm run benchmark:stress
pnpm run benchmark:adversarial
pnpm run devOpen the Vite URL shown by the command and run the incident demo.
Primary live demo:
http://101.201.33.56/
Live Alibaba proof endpoint:
http://101.201.33.56/api/alibaba/proof
Fallback runnable workspace:
https://stackblitz.com/github/Oxygen56/aegisops-autopilot?startScript=dev
GitHub Pages target:
https://oxygen56.github.io/aegisops-autopilot/
Pages demo reel target:
https://oxygen56.github.io/aegisops-autopilot/?reel=1
Blog/Social Post Prize page:
https://oxygen56.github.io/aegisops-autopilot/blog/qwen-cloud-aegisops-autopilot.html
The Alibaba ECS deployment runs the full Node API and exposes Qwen Cloud provider metadata at /api/health without leaking credentials. Public reviewer mode may run deterministic fixtures to avoid exposing or burning a private API key; setting DASHSCOPE_API_KEY or QWEN_API_KEY flips the same backend into live Qwen Cloud mode. The StackBlitz workspace uses .stackblitzrc to run pnpm run dev on launch as a fallback. GitHub Pages is deployed by the repository Pages workflow as a static click-through demo that falls back to deterministic offline fixtures when /api/* is unavailable.
QWEN_API_KEY=sk-...
QWEN_BASE_URL=https://dashscope.aliyuncs.com/compatible-mode/v1
QWEN_MODEL=qwen-plusDASHSCOPE_API_KEY is also accepted. China mainland DashScope keys should use https://dashscope.aliyuncs.com/compatible-mode/v1; international DashScope keys can use https://dashscope-intl.aliyuncs.com/compatible-mode/v1. Do not commit .env files.
AegisOps exposes a judge-verifiable tool surface for Qwen-style orchestration:
- Qwen request body: five OpenAI-compatible function schemas in the
toolsfield, livetool_calls, androle=toolresult messages - OpenAPI spec:
agents/aegisops/openapi.yaml - Capability manifest:
agents/aegisops/cap-manifest.json - MCP stdio server:
pnpm run mcp:stdio - Tool docs:
docs/QWEN_TOOLS.md
HTTP tool example:
curl -sS http://127.0.0.1:8787/api/tools/policy_check \
-H 'content-type: application/json' \
-d '{"incidentId":"support-pii-leak-risk"}'- Unit tests:
pnpm run test - Production build:
pnpm run build - End-to-end API smoke:
pnpm run smoke - Fixture eval:
reports/eval_report.md - Ablation eval:
reports/ablation_report.md - Stress benchmark:
reports/stress_benchmark.md - Adversarial authority benchmark:
reports/adversarial_authority_benchmark.md - Verified live Qwen smoke proof:
reports/live_qwen_smoke_proof.mdrecordsqwen-cloud,qwen-plus, five tool schemas, latency, and redacted credential state - Experiment ledger:
reports/experiment_board.md - Judge evidence bundle:
reports/judge_evidence_bundle.md - Judge demo transcript:
reports/judge_demo_transcript.md - Video asset audit:
reports/video_asset_audit.md - Final preflight:
pnpm run final:preflightwritesreports/final_preflight.md - Submission audit:
reports/submission_audit.md - Qwen integration audit:
reports/qwen_integration_audit.md - Model ops report:
reports/model_ops_report.md - Build provenance:
reports/build_provenance.md - Visible rubric evidence UI:
src/client/main.tsxrenders the 30/30/25/15 judging map in the dashboard
- Brief:
reports/brief.md - Architecture:
docs/ARCHITECTURE.md - Upload-ready architecture diagram:
docs/architecture/aegisops-architecture.svg,docs/architecture/aegisops-architecture.png - Qwen tools:
docs/QWEN_TOOLS.md - Judge packet:
docs/JUDGE_PACKET.md - Build provenance:
docs/BUILD_PROVENANCE.md - Judge evidence bundle:
reports/judge_evidence_bundle.md - Adversarial authority benchmark:
reports/adversarial_authority_benchmark.md - Judge quickstart:
docs/JUDGE_QUICKSTART.md - Rubric scorecard:
docs/RUBRIC_SCORECARD.md - Rubric evidence UI: dashboard panel titled
Judge rubric evidence - Official requirements matrix:
docs/OFFICIAL_REQUIREMENTS_MATRIX.md - Impact case:
docs/IMPACT_CASE.md - Judge demo transcript:
reports/judge_demo_transcript.md - Screenshot:
docs/screenshots/aegisops-dashboard-viewport.png - Static demo screenshot:
docs/screenshots/pages-static-reel.png - Demo video pack:
docs/VIDEO_SUBMISSION.md - Demo video upload metadata:
docs/VIDEO_UPLOAD_METADATA.md - Video asset audit:
reports/video_asset_audit.md - Alibaba Workbench screenshot proof:
docs/screenshots/alibaba-workbench-proof.png - Alibaba Workbench screenshot checklist:
docs/ALIBABA_WORKBENCH_SCREENSHOT.md - Alibaba proof recording:
docs/ALIBABA_PROOF_RECORDING.md - Demo script:
docs/DEMO_SCRIPT.md - Judge notes:
docs/JUDGE_NOTES.md - Publishing:
docs/PUBLISHING.md - Devpost copy:
submissions/devpost_fields.md - Final submission runbook:
submissions/FINAL_SUBMISSION_RUNBOOK.md - Alibaba deployment pack:
infra/alibaba/DEPLOYMENT.md - Full package:
buidl/package/