Published in full

The Kill Log

1226 product ideas generated and then killed, with the exact reason each one died. Everybody publishes their winners. This is the other half.

Data measured , page built 22 September 2026 at 16:10 UTC. Most recent judgement 22 September at 15:58 UTC.

1250drafted
1226killed
24survived
98% rejection rate

Why publish this

We run a system that reads regulatory filings, standards bodies, incident disclosures and practitioner forums, looks for problems that are both newly solvable and provably painful, and drafts software ideas against them. It killed 1226 of the last 1250. That ratio is not a failure, it is the product: the value is in refusing things cheaply, and the reasoning is more useful published than hidden.

The other half is what the market needs that does not exist yet: the few that cleared every evidence test, published in full with what changed to make them possible and who is on record being in pain.

Why they die

The most common reasons, counted. A pattern here says more about a market than any single surviving idea does.

ReasonCount
no specific new capability, only a research theme296
[auto] horizontal/commodity tool (horizontal-tool) in an incumbent-owned market,...42
[auto] horizontal/commodity tool (horizontal-tool, marketing-commodity) in an...26
pain_evidence scored 5, floor is 66
No specific new capability, only a research theme.4
pain is inferred rather than evidenced4
No specific new capability, only a research theme, and pain is inferred from a news...2
no specific new capability, only a research theme, and pain is inferred rather than...2
The native platform AWS Bedrock AgentCore already provides memory lifecycle...1
The pain is vendor marketing narrative from platform companies selling enterprise...1

The log

Most recent first. Nothing edited, nothing flattering removed.

AI Agent Behavior Divergence Detector

Ingests AI agent tool-use logs and flags actions that diverge from declared scope, returning a report of suspicious behaviors

Killed: No specific new capability, only a research theme; pain is inferred from news commentary rather than stated by practitioners; audience is not cleanly enumerable.

AI Agent Blast Radius Mapper

You input an AI agent's declared tools, permissions, and integrations, and the software maps the lateral movement paths and data access an autonomous system could discover from that starting position.

Killed: No specific new capability in the supply signals, only thematic commentary on AI agent governance, and the core pain of unexpected agent paths is an open research problem not addressable by a buildable application.

Self-managed GitLab instance vulnerability scanner

User inputs a list of GitLab instance URLs and the software checks each against known CVEs including active path traversal flaws, returning a patch-status report.

Killed: No specific new capability, only a news cycle about a single CVE being patched; the application is either a transient point-in-time scanner or a general vulnerability management tool that has been buildable and unexciting for a decade.

AI Coding Agent Secret Firewall

Ingests codebase context intended for an AI coding agent, scans and redacts secrets, and outputs a sanitized context package.

Killed: no specific new capability, only a research theme

AI Code Review Interview Assessor

Hiring managers select a role and stack; the software generates AI-produced pull requests with planted defects and presents them to candidates for review; it returns a scored assessment of verification skill.

Killed: No specific new capability, only a research theme; the supply signals describe the problem worsening rather than naming a new tool, API, or model capability that enables a solution not possible before.

Vessel cyber pre-boarding compliance scanner

A shipping company uploads vessel network configs and system inventory, the software checks them against Coast Guard cyber inspection criteria and returns a remediation list before US port entry.

Killed: No specific new capability, only a research theme; the supply signals are general cybersecurity discussions that do not enable a maritime-specific application, and the pain is inferred from news rather than stated by identifiable sufferers.

AI Coding Agent Secrets Redactor

A user routes AI coding agent context through a proxy that scans for secrets, redacts them before they reach the LLM API, and re-injects them into the returned output.

Killed: The anchor pain is a criminal prosecution with no business pain to solve, the supply signals describe an inferred security gap rather than evidenced practitioner pain, and no specific new capability is named, only a research theme.

Microsoft 365 device-code phishing log scanner

Connects to your Microsoft 365 tenant, scans authentication and audit logs for device-code phishing indicators, and outputs flagged sessions with recommended containment actions.

Killed: No specific new capability, only a research theme, and pain is inferred from news coverage rather than stated by identifiable practitioners.

Scanner-to-Patch Prioritization Engine

User uploads a Nessus or Qualys scan export, the software cross-references each CVE against public exploit data and the asset context, and outputs a ranked list of which vulnerabilities are actually exploitable in their environment with evidence chains.

Killed: No specific new capability in the supply signals, only a research theme; the cluster's own evidence warns against the LLM-based approach the application would depend on.

Agentic AI Risk and Liability Assessor

Takes an AI agent's configuration or logs as input and outputs a risk, liability, and governance profile for insurance and compliance purposes.

Killed: no specific new capability, only a research theme

Healthcare AI Vendor Compliance Mapper

A healthcare compliance officer inputs their AI tool inventory and operating jurisdictions, and the software maps each tool against applicable regulatory requirements and flags gaps.

Killed: No specific new capability in the supply signals, only a research theme; the application space is already served by entrenched GRC platforms and nothing provided creates a wedge.

AI Agent Output Validator for Clinical Decision Frameworks

Paste an AI agent's clinical decision output and the software validates it against the applicable decision framework, flagging skipped steps, misapplied thresholds, and hallucinated values.

Killed: The one concrete supply signal already addresses the technical problem at the agent level, the broader pain signals are thematic governance anxiety rather than a stated tool demand, and the audience for a standalone agent output validator is too narrow to enumerate beyond proxy guessing.

LLM Abuse Detection Tool

Ingests API logs and flags malicious LLM usage patterns.

Killed: no specific new capability, only a research theme

AI Engineering Skills Gap Mapper

Input your current role and skills, the software matches you against emerging AI engineering roles and outputs a specific reskilling roadmap.

Killed: Pain is inferred from societal-level survey data with no individual stating a specific need, and the newly possible signal is a research dataset rather than a new technical capability.

AI Agent Behavior Monitor and Risk Flagging

Security teams connect their AI agent deployment logs and the software flags autonomous actions that match patterns of unauthorized access, cyber misuse, or deceptive behavior.

Killed: The pain is a macro policy debate among AI lab executives, not a practitioner-level operational pain, and no specific new capability in the supply signals enables an application that was not buildable before.

AI Agent Incident Tracker and Exposure Checker

A user enters their organization name or domain, and the software checks known AI agent breach incidents and sandbox-escape reports for any exposure to their systems, returning a risk report.

Killed: No specific new capability in the supply signals, only a media theme about AI security fears, and the proposed application would check exposure against a corpus of fewer than ten known incidents, which is a job nobody needs software to do.

Data center cooling architecture comparison tool

A data center operator inputs rack count, power density, location and water constraints, and the software models and compares cooling approaches with water, energy and cost projections.

Killed: Pain is vendor-marketed not practitioner-stated, no specific new capability enables the build, and the application competes against free vendor-provided tools backed by engineering support.

Scan cloud accounts for shadow AI agents and flag access risks

A user connects their cloud account, the software inventories all deployed AI agents and their IAM permissions, and outputs a map of lateral movement paths and excessive access.

Killed: No specific new capability, only a research theme; pain evidence is sponsored content and news coverage, not practitioner statements.

AI Agent Action Approval and Audit Gate

Connects to deployed AI agents via API, intercepts their proposed actions, routes high-risk ones to designated reviewers, and logs every decision for compliance audit.

Killed: No specific new capability, only a research theme. The supply signals are thematic blog posts and surveys about AI governance, not new APIs, models, or standards that make something buildable now that was not before.

Patch Tuesday Prioritizer and Risk Scorer

A user imports their asset inventory and the latest vendor CVE feed, the software cross-references exposure and business context, and outputs a risk-scored prioritized fix queue.

Killed: No specific new capability, only a worsening of an existing problem in a market already served by established platforms.

AI HR Governance Gap Scanner

You input your organization's AI systems and HR use cases, it cross-references them against compliance frameworks and outputs flagged governance gaps and missing controls.

Killed: No specific new capability in the supply signals, only a research theme; the pain is strategic and diffuse rather than a concrete manual workflow, and the responsible role is not yet consistently titled or assigned in most organizations.

Healthcare AI Tool Regulatory Gap Mapper

A healthcare compliance officer inputs their inventory of deployed AI tools and vendors, the software maps each against applicable regulatory frameworks (NIS2, HIPAA, EU AI Act, state AI laws), and outputs a gap analysis flagging missing controls and required actions.

Killed: Supply signals are research themes and commentary, not a specific new capability; pain is secondhand from observers rather than practitioners; and the application competes with entrenched enterprise GRC platforms already adding AI governance.

AI Marketing Content Review and Routing Agent

A marketing team feeds in AI-generated drafts and brand guidelines, the software checks each draft for brand consistency and claim accuracy, and outputs annotated drafts routed to the right human reviewer with issues pre-flagged.

Killed: No specific new capability in the supply signals, only a research theme; the application space is already served by mature review-and-approval platforms.

LLM Gateway Credential Harvesting Detector

Takes your LLM API gateway access logs as input, flags usage patterns consistent with credential harvesting and inference reselling, and outputs specific sessions and keys to revoke.

Killed: Pain is inferred from threat intelligence reports with no sufferer stating the problem, and no specific new capability makes a novel defensive tool buildable, only newly described vulnerabilities addressable by standard scanner patterns.

MIPS Measure Gap Analyzer for Practice Managers

A practice manager uploads their MIPS performance data and the software checks it against current-year measures and thresholds, returning a prioritized list of gaps and corrective actions before submission.

Killed: No specific new capability in the supply signals maps to MIPS compliance or RCM gap analysis; the signals are an AI-in-healthcare theme, and the application competes against entrenched incumbents with EHR integrations a solo builder cannot replicate.

AI Agent Behavior Audit Trail Generator

Ingests AI agent execution logs and produces a compliance audit report of tool calls, data accessed, and anomalous behavior for risk and audit teams.

Killed: The cluster is industry-leader commentary on AI safety, not a stated practitioner pain, and the most concrete signal describes a worsening problem with no specific new capability enabling a buildable solution.

AI-Generated Code Security Divergence Scanner

A developer submits a pull request and a spec, and the software flags where AI-generated code behavior diverges from stated intent or introduces known security weakness patterns.

Killed: No specific new capability, only a research theme; pain is inferred from security news and commentary, not stated by identifiable practitioners.

Vessel Cyber Readiness Pre-Entry Checker

A ship operator inputs their vessel's IT/OT system inventory and network topology, the software cross-checks against Coast Guard boarding criteria and IMO MSC.428(98), and it outputs a risk score and remediation checklist before US port entry.

Killed: No specific new capability in the supply signals, only general cybersecurity themes unrelated to maritime systems, and the commercial audience is too small and hard to enumerate.

AI Code Security Verification Scanner

Ingests AI-generated pull requests and flags security weaknesses and familiar bug patterns.

Killed: cluster is noise, anchor pain is a specific cybercrime sentencing unrelated to the supply signals about AI code verification

Vulnerability Exploitability Prioritization Engine

Takes scanner output and production environment config, deterministically checks which CVEs are actually exploitable in that environment, returns a ranked patch list.

Killed: No specific new capability, only a research theme about AI increasing vulnerability volume, and the space is occupied by well-funded enterprise competitors.

LLM Assisted Attack Detection Platform

Ingests threat intelligence feeds and flags activity patterns characteristic of LLM-assisted attacks.

Killed: No specific new capability, only a research theme.

AI Agent Action Approval Gate and Audit Logger

You connect your AI agent's tool-call output to it, it classifies each action by risk against your policy rules, and routes high-risk actions to a human approval queue while logging everything for audit.

Killed: No specific new capability, only a research theme; the supply signals are restatements of general AI trends, not a released API, model, or standard that makes a particular application newly buildable.

AI skills gap mapper for engineering teams

A manager uploads their team's skill profiles and the software maps them against emerging AI engineering roles from recent job posting analysis, outputting a reskilling priority list.

Killed: The pain is a media narrative about AI job fears, not an operational pain stated by any identifiable practitioner, and the supply signals are research themes rather than a specific new capability.

AI Agent Governance Policy Checker

Ingests an AI agent's access permissions and checks them against selected corporate AI governance frameworks to flag policy violations.

Killed: no specific new capability, only a research theme

Self-managed GitLab KEV exposure checker

User inputs their self-managed GitLab and Artifactory instance details, the software cross-references versions against CISA KEV and active exploitation feeds, and outputs a prioritized patch list with verification.

Killed: No specific new capability, only a news cycle about a known CVE and commentary on eternal vulnerability management problems that existing tools already address.

AI Agent Access Scope Auditor

You register your deployed AI agents and their intended access scopes, and the software compares them against actual cloud IAM permissions to flag overprivileged agents.

Killed: No specific new capability, only a research theme and media commentary; any useful application requires deep cloud IAM integrations that duplicate existing security scanners, and the pain is strategic fear rather than operational practitioner pain.

AI Code Sandbox Verifier for Pull Requests

Ingests a pull request and spec, executes the code in a sandbox against AI-generated tests, and outputs a pass/fail verification report.

Killed: [auto] horizontal/commodity tool (horizontal-tool) in an incumbent-owned market, not a regulated-workflow service

Vulnerability Triage and Prioritization Engine

Ingests scanner output and asset inventory, maps vulnerabilities to business context, and outputs a ranked patch queue.

Killed: no specific new capability, only a research theme

Cloud Vulnerability Exploitability Verifier

Ingests cloud scanner output and uses an AI agent with a code interpreter to run deterministic checks against the environment, returning a prioritized list of actually exploitable flaws.

Killed: The application requires deep, safe integrations with cloud environments and deterministic verification engines that a solo developer cannot build or compete against established enterprise platforms.

Agent Permission Auditor for Cloud AI Deployments

You connect your cloud account, it scans for deployed AI agents and their IAM roles, and outputs a report of overprivileged agents and shared-infrastructure correlated risk.

Killed: The pain is strategic anxiety about an emerging risk, not a concrete manual workflow, and the audience of companies with deployed AI agents is too small and too hard to enumerate from public data.

AI Alert Triage for SOC Analysts

A SOC analyst feeds in alert data from their SIEM, the software classifies which alerts are triggered by legitimate employee AI tool usage versus genuine threats, and outputs a triaged queue with confidence scores and dismissal recommendations.

Killed: [auto] horizontal/commodity tool (horizontal-tool) in an incumbent-owned market, not a regulated-workflow service

AI Agent Action Approval Gate

Intercepts AI agent actions, evaluates them against configured policies, and routes high-risk actions to a human for approval before execution.

Killed: no specific new capability, only a research theme

LLM API Credential Abuse Detector

User connects their LLM provider API or uploads usage logs, the software analyzes patterns for signs of credential theft and abuse, and outputs flagged sessions with recommended key revocations.

Killed: No specific new capability in the supply signals, only a research theme about AI security threats, and the pain is inferred from attacker-side research rather than evidenced by victims.

Semantic Governance Validator for Marketing Data

Ingests raw audience data and marketing campaign specs to output a governed, machine-executable ontology mapping.

Killed: no specific new capability, only a research theme

AI Code Divergence Security Scanner

Ingests AI-generated code diffs alongside their original spec or intent, analyzes for security vulnerabilities and behavioral divergence, outputs a prioritized list of flagged issues for human review.

Killed: No specific new capability, only a research theme; the supply signals are commentary on AI security concerns rather than a released model, API, or standard that enables something previously impossible.

AI Agent Skill Bundler and Tester

A developer inputs a set of MCP servers and skills, the software validates and tests them against prompts, and outputs a packaged plugin file ready to install.

Killed: platforms are already building this natively, no room for a standalone app

AI Code Spec Divergence Checker

Ingests a pull request and its original spec, runs the code, and flags where the AI-generated behavior diverges from the intent.

Killed: The anchor pain is a request for interviewing methodology, which is a document product, and the code review signals describe a separate problem requiring deep CI/CD integration that is not a small standalone application.

AI-generated code vulnerability scanner for PRs

Takes pull requests from AI coding agents, scans them for known vulnerability patterns and supply chain attack indicators, and returns a risk score before merge.

Killed: The anchor pain is a news story about a criminal sentencing, not an expressed pain by any reachable audience, and the supply signals are research themes about AI code verification with no specific new capability named.

AI Agent Sandbox Escape Vulnerability Scanner

User inputs their AI coding agent configuration and the software flags sandbox escape risks against known vulnerability patterns, outputting a prioritized remediation list.

Killed: No specific new capability available to a solo developer, only a research theme of AI security incidents; pain is inferred from news rather than stated by any reachable practitioner; audience is not cleanly enumerable.

Vulnerability Exploitability Prioritization Engine

Ingests vulnerability scanner output and environment context to output a prioritized list of exploitable flaws.

Killed: no specific new capability, only a research theme and opinion pieces on AI architecture.

AI Agent Access Blast Radius Scanner

You input an AI agent's API keys, service accounts, and integration scopes, and it outputs a map of every system and data source the agent can reach, flagging access that exceeds the agent's stated purpose.

Killed: The supply signals are restatements of an AI governance theme rather than a specific new capability, and the evidenced pain is organizational bypass behavior that software cannot fix.

Package Registry Compromise Monitor

Ingests package registry logs and flags anomalous publishing events indicative of compromised maintainer credentials.

Killed: no specific new capability, only a research theme

AI code verification against intent specs

A developer pastes AI-generated code and a natural-language spec, and the tool flags behavioral divergences between what the code does and what the spec intended.

Killed: The cluster is incoherent: the anchor pain is societal AI job-loss anxiety, the supply signals are trend restatements with no specific new capability, and the only workflow pain comes from a single article about a problem that has existed since AI coding assistants shipped over a year ago.

AI agent action auditor for security teams

A security team connects their AI agent logs and the software flags unauthorized or anomalous agent actions for review before execution.

Killed: The anchor pain is an executive policy debate about slowing AI development, not a practitioner pain that maps to a buildable application, and no specific new capability makes an agent audit tool buildable now.

Self-managed GitLab exposure checker

Input a list of your self-managed GitLab and Artifactory instance URLs, it checks each against known CVEs and returns which are vulnerable and need patching.

Killed: No specific new capability in the supply signals, only news about CVEs being exploited; the application is a vulnerability scanner, a well-established category not newly enabled by anything in this cluster.

Patch Tuesday Prioritization Engine

Ingests the monthly Patch Tuesday CVE list and outputs a prioritized patching schedule based on a user's asset inventory.

Killed: no specific new capability, only a research theme

AI Agent Attack Detector

Ingests security alert logs and flags which ones were caused by AI agents.

Killed: no specific new capability, only a research theme

AI Agent Governance Posture Assessor

User inputs their AI agent inventory and access scopes, software cross-references against control frameworks, outputs a gap analysis with flagged risks.

Killed: No specific new capability in the supply signals, only a growing problem theme, and any version buildable by one person in days is a document product that assesses rather than an application that governs.

AI Tool Hours and Duplication Reporter for Team Leads

A team lead connects their team's AI tool accounts and Git repos, the software correlates usage logs with commits and flags duplicated AI-generated code, and outputs a weekly dashboard of hidden hours, duplication patterns, and spend efficiency.

Killed: No specific new capability, only a research theme: every supply signal is a survey result, trend commentary, or vendor marketing, none represents a new API, model, or released capability that makes an application newly buildable.

Vulnerability Exploitability Verifier Against Live Infrastructure

Users connect their cloud account and import vulnerability scanner output, the software cross-references findings against actual running infrastructure to deterministically check which vulnerabilities are exploitable in their environment, and outputs a prioritized fix list with evidence.

Killed: No specific new capability, only a research theme, and the underlying vulnerability prioritization problem is already served by established platforms.

AI Agent Configuration Risk Scanner for Governance Teams

Users upload their AI agent configurations and the software analyzes them against governance controls to produce a prioritized risk report with remediation steps.

Killed: The pain is inferred from news stories describing strategic concerns, not evidenced as a specific workflow someone does by hand, and the supply signals are primarily thematic restatements rather than a specific new capability.

AI Alert Triage for Security Operations Centers

A SOC team feeds in their alert stream and the software flags which alerts are triggered by legitimate internal AI tool usage versus real threats, returning a triaged queue with attribution.

Killed: No specific new capability in the supply signals, only a research theme about AI adoption that creates the pain but supplies nothing newly buildable.

AI Agent Action Approval Gateway

You connect your AI agents and configure which actions need human sign-off; the software intercepts agent actions, checks them against your rules, and queues risky ones for review before they execute.

Killed: no specific new capability, only a research theme

LLM Gateway Security Audit Scanner

You input your LLM gateway URL and configuration, the software runs the attack checks described in recent incident reports against it, and it returns a prioritized list of exploitable security gaps.

Killed: The cluster is a news theme about LLM and agent security incidents with no buyer-stated pain, no specific new capability for a solo builder, and an audience that is too small and not self-identifying.

AI Marketing Agent Governance API

Upload your audience taxonomy and governance policies, the software returns an API endpoint that AI marketing agents query to get deterministic allow or deny decisions before acting on audience data.

Killed: No specific new capability, only a research theme; pain is architectural and inferred from conference talks rather than stated by practitioners doing a task by hand.

Spec-to-Code Divergence Flagging Tool

User uploads a natural language spec and AI-generated code, the software flags where implementation diverges from stated intent, returning a line-referenced report of mismatches and security patterns.

Killed: No specific new capability, only a research theme; the supply signals are commentary on AI problems, not a released API or model that enables something new, and the audience cannot be enumerated by any searchable signal.

MCP Server Compatibility Scanner and Bundle Builder

A developer uploads their AI coding agent config, the software scans installed MCP servers and skills for conflicts and overlap, and outputs a report of which servers work together plus recommended plugin bundles for their stack.

Killed: The pain is mild and vendor-solvable, the specific management pain is inferred rather than directly evidenced, and the audience of developers actively struggling with multiple MCP servers is too small and too early to enumerate reliably for outreach.

AI-generated code security verification gate

Engineering teams submit pull requests, the software runs security and spec-compliance analysis on AI-generated code, and returns a pass or fail with flagged vulnerabilities before merge.

Killed: The supply signals are research themes and commentary about AI code security, not specific new capabilities, and the pain is inferred from trend articles rather than stated by identifiable users.

AI Agent Sandbox Escape Activity Scanner

You feed it execution logs from your AI coding agent and it flags behavior patterns consistent with sandbox escape or unauthorized access, returning a prioritized alert report.

Killed: Pain is entirely inferred from news coverage rather than stated by practitioners, and the supply signals are reports about enterprise products and vulnerabilities, not a specific new capability an indie developer can build on.

Patch Triage Engine for Patch Tuesday Overwhelm

Ingests CVE feeds and your asset inventory, cross-references active-exploitation and exploitability signals, and outputs a ranked patch queue scoped to your environment.

Killed: No specific new capability, only a research theme: the supply signals describe AI creating more vulnerabilities and AI agents misbehaving, none of which enables a new application that existing vulnerability prioritization platforms do not already cover.

AI Agent Compliance Gap Screener

A user describes their AI agent deployment and the software matches it against compliance frameworks to flag governance gaps.

Killed: no specific new capability, only a research theme

AI Secret Scanner for Mobile App Packages

Upload an APK or app bundle, the software analyzes it for hardcoded secrets and credentials that AI-assisted attackers could extract, and returns a prioritized list of exposed secrets with file locations and remediation steps.

Killed: No specific new capability in the supply signals, only a research theme about AI abuse, and the pain is inferred from news stories rather than stated by identifiable users.

AI Generated Code Spec Verification Scanner

A developer pastes a spec and AI-generated code, the software checks for divergences from intent and known security weakness patterns, and returns a flagged report.

Killed: The supply signals are research themes and trend observations, not a specific new capability, and the anchor pain is societal anxiety about AI job loss rather than an operational problem a software application can solve.

AI-Generated PR Verification Triage Queue

Connects to your GitHub, ingests incoming pull requests, identifies AI-generated changes, risk-scores each PR, and outputs a prioritized review queue with specific verification checkpoints.

Killed: The anchor pain is a policy debate among AI lab executives about pacing frontier model development, not a software job someone needs done, and the supply signals are a research theme rather than a specific new capability.

Self-Managed GitLab Instance Vulnerability Checker

Enter one or more GitLab instance URLs, the tool probes the version endpoint and commits API for the CVE-2026-85706 path traversal flaw, and returns which instances are exploitable and which patch version to install.

Killed: No specific new capability beyond a new CVE being disclosed; pain is inferred from news coverage rather than stated by practitioners; the most plausible application is a transient single-vulnerability scanner competing with established vulnerability management tools.

Patch Tuesday CVE Prioritizer for Your Environment

User inputs their Microsoft product inventory and the month's CVE list, the software cross-references exposure data and outputs a ranked patching schedule with business-risk scores.

Killed: No specific new capability, only a worsening problem; established vulnerability management platforms already address this need.

SOC AI Agent Alert Triage and Noise Filter

SOC teams connect their SIEM or EDR alert feed, the software classifies which alerts originate from legitimate internal AI tool and agent usage versus real threats, and outputs a triaged queue with AI-origin noise collapsed into summary batches.

Killed: No specific new capability, only a research theme; the supply signals describe agent proliferation and infrastructure for building agents, not a new defensive capability that makes this application newly buildable.

AI Code Duplication and Waste Detector

Ingests a Git repository URL and flags AI-generated code duplication and estimated wasted spend.

Killed: no specific new capability, only a research theme

Cloud Vulnerability Exploitability Confirmer

A user uploads scanner output and grants read-only cloud credentials, and the software runs deterministic verification checks against their infrastructure to confirm which vulnerabilities are actually exploitable, returning a prioritized list with evidence.

Killed: The evidenced pain requires production infrastructure access to solve, creating an insurmountable trust and procurement barrier for a solo builder, and the supply signals are thematic restatements of AI-in-security rather than a specific new capability.

AI Agent Footprint Alert Triage for SOCs

Ingests SIEM alert logs and classifies which are triggered by benign internal AI agent activity versus actual threats, returning a filtered queue.

Killed: no specific new capability, only a research theme

MIPS Measure Gap Checker for Clinical Practices

A practice manager uploads their quality measure data and the software checks it against current MIPS specifications and thresholds, outputting a list of gaps and required documentation actions before submission.

Killed: No specific new capability maps to the anchor pain; the supply signals are a research theme about AI agents in healthcare, not a released capability that enables a specific buildable application.

LLM API Credential Theft Detector

Takes your LLM provider API usage logs as input, analyzes them for patterns indicating stolen or harvested credentials, and returns flagged sessions with evidence of abuse.

Killed: Pain is inferred from security research, not stated by practitioners, and the audience cannot be enumerated by any searchable job title or signal.

AI Code Security Weakness Detector

Ingests code commits and flags security weaknesses introduced by AI coding assistants.

Killed: no specific new capability, only a research theme

AI Code Verification and Compliance Scanner

Ingests a GitHub pull request, analyzes the code diff for security weaknesses, and outputs a list of compliance control violations.

Killed: no specific new capability, only a research theme

AI Infrastructure Configuration Risk Scanner

User ingests their cloud AI workload configuration and the software flags identity over-permissions, egress cost blind spots, storage bottlenecks, and data leakage risks in training pipelines.

Killed: No specific new capability, only a research theme; pain is inferred from editorial content rather than stated by practitioners; audience is diffuse and not sharply enumerable.

Cross-platform AI coding agent plugin manager

Input your project stack and coding agent config, the software scans available skills and plugins across platforms, recommends compatible bundles, and installs them into your agent of choice.

Killed: The platform owners who define the plugin formats are already shipping native catalogs and managers, making a third-party tool structurally outcompeted, and the audience cannot be sharply enumerated from professional profiles.

Kill: no coherent application in this cluster

No application emerges: the anchor is a criminal prosecution news story, and the supply signals are restatements of security themes without a specific new capability or an enumerable audience.

Killed: No specific new capability, only a research theme; the anchor pain is a criminal prosecution news story with no identifiable user stating a problem, and no enumerable audience connects the supply signals.

AI Agent Access and Governance Gap Scanner

A user inputs their AI agent inventory and identity policies, the software maps each agent's access against governance controls, and outputs a prioritized remediation list of overprivileged or ungoverned agents.

Killed: No specific new capability in the supply signals, only a research and journalism theme about AI governance lagging; the concrete application would compete with features being added to identity suites the buyer already owns.

Android App Secret Exposure Scanner

User uploads an APK or provides a package name, the software scans the app for hardcoded secrets and API keys using AI-assisted extraction techniques, and returns a report of exposed credentials with severity ratings.

Killed: Pain is inferred from Anthropic's threat reports rather than evidenced by practitioners, and no specific new capability enables a novel application beyond existing secret scanning tools.

Agent Risk Profile Generator

Ingests AI agent tool definitions and outputs an insurance risk profile.

Killed: no specific new capability, only enterprise platform announcements and a research theme.

AI Agent Sandbox Escape Monitor

Ingests execution logs from AI coding agents, detects unauthorized communication and sandbox escapes, and alerts security teams.

Killed: The application is a specialized SIEM rule set requiring heavy integrations with diverse agent platforms, and the audience of companies with enough autonomous agent volume to need it is currently too small and hard to identify.

AI Code Intent Divergence Detector

A developer pastes AI-generated code and its spec, and the software flags where the code's behavior diverges from the stated intent, surfacing security weaknesses and familiar bug patterns.

Killed: No specific new capability in the supply signals, only trend observations and a methodology article; the strongest application competes with mature existing tools and the core cluster pain is inferred from surveys rather than stated by identifiable people doing a specific job.

AI Code Verification Risk Screener

A user pastes a pull request URL, the software analyzes the diff for risk patterns and verification gaps, and returns a prioritized review checklist and risk score.

Killed: No specific new capability in the signals, only a pain shift from increased code volume; the solution space is already occupied by the platforms that own the PR workflow.

AI Agent Permission Review Auditor

Ingests your deployed AI agent inventory and flags which agents lack completed permission reviews or defined accountability.

Killed: no specific new capability, only a research theme

Vulnerability Exploitability Traversal Engine

Ingests vulnerability scanner output and traverses system evidence to deterministically flag which GitLab and Artifactory flaws are exploitable in production.

Killed: no specific new capability, only a research theme

Patch Tuesday CVE-to-Asset Prioritizer

User uploads their asset inventory and a Patch Tuesday CVE list, and the software ranks patches by exploitability and business impact for their specific environment.

Killed: No specific new capability in the supply signals, only a research theme of increasing vulnerability volume; the problem is real but not newly solvable by a solo builder.

AI Agent Access and Permission Auditor

A user enters their organization's AI agents and the data sources each accesses, and the software checks each agent's permissions against governance controls and returns a compliance gap report with remediation actions.

Killed: Pain is inferred from articles describing an emerging phenomenon, not from practitioners stating a need for this specific tool, and the audience for AI agent access auditing is too emerging to enumerate sharply.

AI Agent Product Visibility Tracker

Ingests a retailer's product categories and competitor URLs, simulates AI shopping agent queries, and outputs a report on their share of voice and recommendations to optimize for agentic discovery.

Killed: [auto] horizontal/commodity tool (horizontal-tool, marketing-commodity) in an incumbent-owned market, not a regulated-workflow service

AI Agent Sandbox Escape Vulnerability Scanner

You upload your AI agent or coding tool configuration files and the software checks them against a database of known sandbox escape vulnerabilities and risky configuration patterns, returning a risk report with remediation steps.

Killed: Pain is inferred from news stories rather than stated by practitioners, the audience cannot be precisely enumerated because AI agent sandbox responsibility is not a published job function, and the vulnerability knowledge base is too thin to support a useful scanner.

AI ITSM Output Validator

Ingests AI-generated ITSM ticket resolutions and flags low-confidence outputs or integration failures for human review.

Killed: no specific new capability, only a research theme

AI Usage Audit Dashboard for Team Leads

A team lead connects their team's AI tool accounts, the software pulls and categorizes usage logs, and outputs a dashboard showing where AI hours and spend are going with flagged waste patterns.

Killed: No specific new capability in the supply signals, only thematic observations about AI adoption, and the pain is diffuse burnout rather than a concrete manual job that software can now automate.

AI Agent Sandbox Escape Scanner

Ingests AI coding agent logs and flags activity patterns consistent with sandbox escape or unauthorized privilege escalation.

Killed: Pain is inferred from news reporting rather than stated by identifiable users, the supply signals describe a patched CVE and a model release rather than a new building capability, and the audience cannot be enumerated without guessing at proxies.

Patch Tuesday Prioritization Planner

Ingests the monthly CVE list and your software inventory, then outputs a prioritized patching schedule based on exploitability and asset exposure.

Killed: no specific new capability available to the operator, only vendor announcements of closed AI features.

Vulnerability Prioritizer With Business Context

A user uploads a vulnerability scan export and the software returns a ranked fix list based on inferred business context and real exploitability, not raw CVSS scores.

Killed: [auto] horizontal/commodity tool (horizontal-tool) in an incumbent-owned market, not a regulated-workflow service

LLM API Abuse Detection Tool

Ingests LLM API logs and flags sessions exhibiting stolen inference capacity or reasoning trace extraction.

Killed: The pain is inferred from security research rather than evidenced by a user, and the supply signals are restatements of a theme rather than a specific new capability.

Automated AI Code Verification Reviewer

Ingests pull requests and flags AI-generated code anomalies for human review.

Killed: no specific new capability, only a research theme

AI Workload Infrastructure Risk Scanner

User uploads Kubernetes manifests and cloud IAM policies for an AI workload, the software flags storage bottlenecks, identity over-grants, egress cost blind spots, and single-region failure risks, and returns a prioritized remediation list.

Killed: No specific new capability in the supply signals, only an engineering theme, and the pain is inferred from editorial and vendor content rather than evidenced by users.

AI Vulnerability Triage for Essential Services

Small banks and utilities upload vulnerability scan results and get AI-prioritized remediation plans using Daybreak cyber models.

Killed: Pain is inferred from OpenAI's marketing for its own program rather than stated by actual sufferers, Cloudflare is already building the obvious application on Daybreak, and a solo developer likely cannot access the Daybreak cyber models that make this newly possible.

AI Coding Agent Plugin Discovery and Bundle Manager

Ingests your project tech stack and dependencies, recommends which AI coding agent skills and MCP plugins to install, and outputs curated bundles with install commands.

Killed: The audience cannot be enumerated by standard professional profile fields, the pain is mild inconvenience rather than costly friction, and the hyperscalers are already solving this natively with free first-party plugin catalogs.

Patch Prioritization Engine

Ingests your monthly CVE list and asset inventory, applies business context rules, and outputs a ranked patching schedule.

Killed: no specific new capability, only a research theme

AI-generated code security verification scanner

A developer pastes in AI-generated code and the tool flags security weaknesses and divergences from the stated spec.

Killed: The pain is an author's observation about AI code security with no quoted practitioner pain, the supply signals are restatements of a theme rather than a specific new capability, and the anchor pain about a ransomware criminal is completely disconnected from the supply signals.

Post-Quantum Cryptography Readiness Scanner

Ingests a list of domains or IP ranges, scans their TLS handshakes and DNSSEC records, and outputs a report flagging which external assets still rely on vulnerable pre-quantum cryptography.

Killed: The evidence explicitly states the threat is off the radar and not resourced because other security concerns take precedence, meaning there is no acute operational pain driving a purchasing decision today.

AI Agent Sandbox Configuration Auditor

Ingests your AI agent configuration files and flags risky permissions that allow sandbox escapes or internet access.

Killed: The pain requires runtime network monitoring or platform-level sandboxing that is too complex for a solo developer to build in days, and the supply signals are disconnected news items rather than a specific new API or capability enabling a lightweight solution.

AI Agent Access and Behavior Auditor

You upload your AI agent's configuration and tool call logs, the software maps what systems and data the agent can reach, flags risky access paths and policy violations, and outputs a governance gap report mapped against compliance frameworks.

Killed: No specific new capability, only a research theme and vendor product announcements; the one shipped capability (Bedrock AgentCore) is a platform feature, not an enabling primitive for a third-party application.

GitLab Instance Vulnerability Scanner

Ingests a list of GitLab instance URLs and probes them for the CVE-2026-85706 path traversal flaw, returning a list of vulnerable servers.

Killed: no specific new capability, only a news cycle about a CVE and opinion pieces on AI agents.

AI PR diff decomposer and spec verifier

You paste a pull request URL or diff, the software decomposes it into logical review units, cross-references each against your stated spec or intent, and outputs a prioritized list of flagged issues grouped by concern.

Killed: No specific new capability, only a research theme, and the application space is already crowded with well-funded competitors doing exactly this.

AI Code Spec Divergence Detector

Ingests a natural language spec and AI-generated code, generates edge-case tests, runs them, and flags where the code's behavior diverges from the spec's intent.

Killed: no specific new capability, only a research theme and market trends.

Cloud Identity Token Compliance Scanner Against NIST Guidelines

A user connects their cloud account or uploads an identity token inventory, the software checks each token and assertion against the finalized NIST/CISA guidelines, and outputs a prioritized list of violations with remediation steps.

Killed: [auto] horizontal/commodity tool (horizontal-tool) in an incumbent-owned market, not a regulated-workflow service

AI Agent Spend and Exception Monitor

You connect your AI platform API keys and agent logs, the software pulls usage and cost data and flags low-confidence outputs, and you get a dashboard with cost alerts and an exception queue for human review.

Killed: No specific new capability, only a research theme about AI creating overhead work, and the application competes against native dashboards from the platforms already causing the pain.

AI Workflow Time Tracker and Efficiency Auditor

A user connects their AI tool accounts and the software logs actual time spent across AI workflows, producing a report comparing expected efficiency gains against real hours invested.

Killed: The pain is diffuse organizational burnout from AI adoption rather than a specific workflow problem software can solve, and the supply signals are thematic trends rather than a specific new capability.

The gates each one had to clear

Is it software
A running loop with inputs and outputs, not a document product.
Reachable audience
How many individually identifiable people could be reached about it within weeks.
Evidenced pain
Somebody stated it in their own words, or a regulator set a dated obligation. Inferred pain fails.
Findable audience
Specific enough to search for by role and sector.
Newly possible
A capability that did not exist last year. Recency is not novelty, and a research theme is not a capability.

An idea dies on the first gate it misses. Most die on the last one.

The corpus behind the judgement

723 compliance frameworks, 20,473 controls, 332,959 cross-framework mappings, 531 frameworks verified against source documents.

See the corpus