Model or dataset
Yeti-791/Tsec-Hackathon avatar
Yeti-791/Tsec-Hackathon

Tsec-Hackathon: a navigation page whose top 20 table shows seven rows, and whose participant list is a JPEG

腾讯云智能渗透黑客松 Official repository of Tencent Cloud Intelligent Penetration Hackathon. Showcasing top open-source projects of LLM-based autonomous penetration agents, including multi-agent collaboration, automated penetration, AI-driven offensive security, and intelligent attack-defense solutions.

818 stars101 forksPythonLicense varies

At a glance

What is it?
The official resource repository for Tencent Cloud's intelligent penetration agent competition. It holds defence decks from two editions as PDFs, points at twenty team projects, and carries its own caveats: a competition date in April 2026 attached to every capability claim, an introduction that promises the top ten of both editions above a header that says twenty.
Who is it for?
Use Tsec-Hackathon as an index. It is the fastest way to reach twenty open source penetration agent projects and the decks their teams presented, and it saves you the search.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 21 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.

Editorial analysis

A navigation page with no source code at its top level

The repository root holds a gitignore, this README, a Markdown list file with an awesome-list name, two JPEG images, and two directories named for the first and second editions of the competition. There is no package manifest, no build file and no source tree at the root, while the language classifier records the project as Python. That classification is not explained anywhere on the page. What the repository actually stores is documents: defence presentation decks from the winning teams, uploaded as PDF files into a folder inside the second edition directory, and linked from the table with percent-encoded Chinese paths. That makes it an archive with an index rather than a project you would depend on, and the distinction matters before you clone it expecting to build something.

A top 20 table that shows seven rows and skips four ranks

The section is titled as a navigation list for the top twenty teams of the second edition, sorted by final competition result. The rows that are present carry ranks 1, 3, 7, 17, 18, 19 and 20. Ranks two, four, five, six, and eight through sixteen have no row in the part of the table on the page. The four bottom ranks are also empty in a second way: the columns for the team's core highlight, the defence deck and the video all hold a dash, so the only thing those rows carry is a link to an open source repository. A reader scanning the table will see the winners described in detail and the tail of the field reduced to bare links, and nothing on the page says the intervening rows are simply absent rather than withheld.

The introduction says ten teams, the header says twenty

Two statements about scope sit within a few paragraphs of each other and do not agree. The narrative paragraph says the section collects the open source repositories of the top ten teams from the online stage of both competitions, which would be twenty entries across two editions. The heading and the text under it say the top twenty teams of the second edition alone. The table itself has no first-edition rows at all, so on the evidence of the page the second reading is the accurate one and the first is left over from an earlier plan. The English summary above it compounds the drift by describing the repository as holding the materials of the first hackathon, while the rest of the page documents two editions.

The only cost figure on the page has no methodology

One row records a monetary number. The team at rank three is credited with a blackboard system, an ant colony algorithm and emergent behaviour, with equal workers taking tasks dynamically and an explicit rejection of predefined role division, described as a projection of human limitations. The same cell adds two more claims: it was the only entry in the competition to receive full marks across the board, and it did so at a cost of 7,692 yuan. That is the only cost figure anywhere in the document. Nothing states what the figure covers, whether it is model spend, infrastructure, or both, how many targets were run, or what the other teams spent. Read it as a headline, not as a benchmark, because nothing on the page lets you compare it to anything.

One link carries a misspelled name and a trailing space

The row at rank nineteen points at a repository whose own name appears with a transposed pair of letters, using a spelling of the company that differs from the one used everywhere else on the page, and the link target ends with a space before the closing bracket. Both are small, and both are the kind of thing that survives because nobody clicks it during editing. The other three bottom rows are clean: one points at a project with a short name, another at another short name, and rank twenty at a repository whose name describes the event and the year. A link table is only as good as its least visited row, and this one has three rows that carry no description to compensate for a broken or misspelled target.

The participant list is a picture of a table

Two JPEG files sit at the root of the repository: one is the poster for the competition, the other is the list of participating teams. A list of entrants delivered as an image rather than as text or a table means the names cannot be searched, indexed, copied or counted by anything reading the repository. The README already states the aggregate figures in prose, more than 800 teams and more than 1,000 participants across the two editions, so the totals are available without the image. The individual names are not. For anyone trying to trace which team produced which project, or to work out how many of the entrants shipped code, the picture is the only source and the only source that resists being read by a tool.

A named individual's contact details sit in the file

The link block at the top of the page lists four destinations: the competition home page, the competition platform, what is described as an agent social forum, and a video series hosted elsewhere. Three of the four share one domain, and the forum is described as a social feed rather than a documentation site. The fourth line of that block is a messaging contact given as a WeChat identifier, followed by a person's name and their role, described as the person responsible for attack and defence at the sponsoring laboratory. Publishing a direct personal contact for an event role is a normal thing for an event page to do, and it is also the one line on the page that will age badly, since it will still resolve after the role changes hands.

The page dates its own claims and expires them

Above the table there is a single line stating the competition took place in April 2026, followed by a parenthetical note that because of the pace of technical development, the capabilities shown represent only that point in time. It is an unusual and welcome admission in a leaderboard document: the architectures being compared were current in spring 2026 and the page says so instead of implying they still are. The rest of the freshness picture is thinner. There are no releases, and the repository's last push is dated 14 September 2026, about five months after the competition it documents. The first edition's contributions appear only as three links in a high-star list, with star counts attached to two of the three projects.

Editorial conclusion

Use Tsec-Hackathon as an index. It is the fastest way to reach twenty open source penetration agent projects and the decks their teams presented, and it saves you the search. Four things to know before you rely on it. The table is not complete in the part that is easy to skim: the visible rows carry ranks 1, 3, 7 and then jump to 17 through 20, and the last four have no description, no deck and no video at all. The decks are PDFs stored in the repository itself, which makes it a document archive rather than a code project, and the recorded language does not match anything at the top level. The page attaches an expiry date to itself, saying the competition ran in April 2026 and that the capabilities shown represent only that point in time. And the project's own framing is a competition leaderboard: one row records a cost figure in yuan with no methodology attached. If you want to reproduce any of these architectures, go to the linked repositories and read their licences. Nothing here is licensed by this page.

Frequently asked questions

What does the Tsec-Hackathon repository contain?

Documents and links rather than code. The top level holds this README, an awesome-list style Markdown file, two JPEG images, and one directory per competition edition, with defence presentation decks stored as PDFs inside them.

How many team projects does Tsec-Hackathon link to?

The section is presented as a top twenty list for the second edition, but the visible table carries seven rows, at ranks 1, 3, 7, 17, 18, 19 and 20. The bottom four rows carry no description, no deck and no video.

Which Tsec-Hackathon project is reported as full marks at a stated cost?

The team at rank three, whose row credits a blackboard system with an ant colony algorithm, and records it as the only full marks entry at a cost of 7,692 yuan. No breakdown of that figure is given.

When did the second Tsec-Hackathon competition take place?

April 2026, according to the line above the team table, which also notes that because of the pace of technical development the capabilities shown represent only that point in time.

Official sources

  1. Issues
  2. Project website
  3. README
  4. Yeti-791/Tsec-Hackathon on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/yeti-791-tsec-hackathon.svg)](https://hysenlabs.com/projects/yeti-791-tsec-hackathon)