Trippy
Trust signals for agent-driven hiring.
Inspiration
Generative AI created a trust problem on both sides of hiring. Recruiters struggle with automated applications, while candidates face fake recruiters and malicious job pages.
Instead of using unreliable AI-writing detectors, we focused on one measurable question:
Did an application agent follow an untrusted instruction embedded in the hiring workflow?
What it does
Trippy adds a harmless, session-specific canary to an optional application field.
If a browser agent reads the page instruction and submits the unique canary, Trippy records an Agent Exposure Signal. This is evidence for review—not a fraud verdict or automatic rejection.
Recruiters can:
- Review saved applications
- Inspect application-specific timelines
- Request candidate verification
- Track completed verifications
Candidates can also use Trust Scan, powered by Tavily, to compare a job page or recruiter domain with likely official company sources.
How we built it
Trippy uses:
- Next.js, React, and TypeScript
- HMAC-SHA256 signed canaries
- Private Vercel Blob storage
- Resend for verification emails
- Tavily for public-web research
Each canary contains a random value, nonce, signature, and 15-minute expiration. The backend validates the signature and checks whether the submitted value exactly matches the session’s canary.
Verification links use application-specific tokens. Opening the link verifies the correct application and automatically adds the event to its saved timeline.
Challenges we ran into
Our biggest challenge was separating agent exposure from fraud. Following an unsafe instruction does not prove malicious intent, so Trippy never automatically rejects candidates.
We also replaced browser local storage with persistent server-side records so verification links could update the correct application across browsers and devices.
Other challenges included secure token handling, email-provider restrictions, and keeping Tavily results evidence-based.
Accomplishments that we're proud of
We built a complete working flow:
- Generate a signed canary
- Observe the agent’s action
- Save the application and evidence
- Send a verification link
- Verify the correct application
- Update its audit timeline automatically
- Scan suspicious hiring URLs using live Tavily evidence
The core exposure decision is deterministic and explainable—not an opaque AI score.
What we learned
We learned that narrow behavioral signals can be more useful than broad AI-generated probability scores.
We also learned that trust products must clearly communicate what the evidence proves and what it does not prove. Fair verification is just as important as detection.
What's next for Trippy
Next, we plan to add:
- Recruiter authentication
- Multi-tenant database storage
- Greenhouse and Lever integrations
- Real Playwright or remote browser agents
- Browser-session replays
- Verified employer domains
- Look-alike domain monitoring
- Candidate privacy and retention controls
Our goal is to make Trippy a lightweight trust layer for hiring workflows increasingly operated by AI agents.
Built With
- agentic
- agents
- ai
- apis
- blob
- detection
- hiring
- hmac-sha256
- injection
- next.js
- node.js
- prompt
- react
- resend
- rest
- security
- tavily
- technology
- typescript
- vercel
- verification
- web
- workflows
Log in or sign up for Devpost to join the conversation.