Trippy

Trust signals for agent-driven hiring.

Inspiration

Generative AI created a trust problem on both sides of hiring. Recruiters struggle with automated applications, while candidates face fake recruiters and malicious job pages.

Instead of using unreliable AI-writing detectors, we focused on one measurable question:

Did an application agent follow an untrusted instruction embedded in the hiring workflow?

What it does

Trippy adds a harmless, session-specific canary to an optional application field.

If a browser agent reads the page instruction and submits the unique canary, Trippy records an Agent Exposure Signal. This is evidence for review—not a fraud verdict or automatic rejection.

Recruiters can:

  • Review saved applications
  • Inspect application-specific timelines
  • Request candidate verification
  • Track completed verifications

Candidates can also use Trust Scan, powered by Tavily, to compare a job page or recruiter domain with likely official company sources.

How we built it

Trippy uses:

  • Next.js, React, and TypeScript
  • HMAC-SHA256 signed canaries
  • Private Vercel Blob storage
  • Resend for verification emails
  • Tavily for public-web research

Each canary contains a random value, nonce, signature, and 15-minute expiration. The backend validates the signature and checks whether the submitted value exactly matches the session’s canary.

Verification links use application-specific tokens. Opening the link verifies the correct application and automatically adds the event to its saved timeline.

Challenges we ran into

Our biggest challenge was separating agent exposure from fraud. Following an unsafe instruction does not prove malicious intent, so Trippy never automatically rejects candidates.

We also replaced browser local storage with persistent server-side records so verification links could update the correct application across browsers and devices.

Other challenges included secure token handling, email-provider restrictions, and keeping Tavily results evidence-based.

Accomplishments that we're proud of

We built a complete working flow:

  • Generate a signed canary
  • Observe the agent’s action
  • Save the application and evidence
  • Send a verification link
  • Verify the correct application
  • Update its audit timeline automatically
  • Scan suspicious hiring URLs using live Tavily evidence

The core exposure decision is deterministic and explainable—not an opaque AI score.

What we learned

We learned that narrow behavioral signals can be more useful than broad AI-generated probability scores.

We also learned that trust products must clearly communicate what the evidence proves and what it does not prove. Fair verification is just as important as detection.

What's next for Trippy

Next, we plan to add:

  • Recruiter authentication
  • Multi-tenant database storage
  • Greenhouse and Lever integrations
  • Real Playwright or remote browser agents
  • Browser-session replays
  • Verified employer domains
  • Look-alike domain monitoring
  • Candidate privacy and retention controls

Our goal is to make Trippy a lightweight trust layer for hiring workflows increasingly operated by AI agents.

Built With

  • agentic
  • agents
  • ai
  • apis
  • blob
  • detection
  • email
  • hiring
  • hmac-sha256
  • injection
  • next.js
  • node.js
  • prompt
  • react
  • resend
  • rest
  • security
  • tavily
  • technology
  • typescript
  • vercel
  • verification
  • web
  • workflows
Share this project:

Updates

Submission history