Published in full

The Kill Log

60 product ideas generated and then killed, with the exact reason each one died. Everybody publishes their winners. This is the other half.

Updated . Most recent judgement 26 July at 22:36 UTC.

Why publish this

We run a system that reads regulatory filings, standards bodies, incident disclosures and practitioner forums, looks for problems that are both newly solvable and provably painful, and drafts software ideas against them. It killed 60 of the last 64. That ratio is not a failure, it is the product: the value is in refusing things cheaply, and the reasoning is more useful published than hidden.

The other half is what the market needs that does not exist yet: the few that cleared every evidence test, published in full with what changed to make them possible and who is on record being in pain.

Why they die

The most common reasons, counted. A pattern here says more about a market than any single surviving idea does.

ReasonCount
no specific new capability, only a research theme16
The audience of developers actively deploying stateless MCP servers in production is too small and early to enumerate at scale, an1
No specific new capability, only a research theme; the pain is real but the supply signals are blog posts about AI in security, no1
No specific new capability is evidenced in the cluster; the supply signals describe new attack vectors and a platform's program re1
No specific new capability, only a policy lobbying theme with no enacted regulation and no practitioner-stated pain.1
No specific new capability in the supply signals, only news stories and a research paper; the proposed application is a commodity 1
The supply signals are thought leadership and research themes with no specific new capability, and the application requires deep s1
No specific new capability, only a research theme: the supply signals are trend reports and vendor blog posts, and the underlying 1
The anchor pain (a patched Zimbra zero-day) and the supply signals (AI agent prompt injection and OAuth abuse incident reports) de1
No specific new capability, only a research theme: the supply signals are thought leadership pieces and an article describing some1

The log

Most recent first. Nothing edited, nothing flattering removed.

8-K Cybersecurity Incident Disclosure Drafter

Users input incident details and the software drafts the required SEC 8-K cybersecurity incident disclosure text.

Killed: no specific new capability, the SEC rule is from 2023 and the supply signals are unrelated news items.

AI Search Visibility Tracker for Agencies

An agency enters a client brand and category prompts, the software queries ChatGPT, Google AI Overviews and Perplexity, and returns a dashboard showing whether and how the brand appears across AI-generated answers over time.

Killed: No specific new capability in the supply signals, only a general AI growth theme; the core technology has been buildable since 2023 and the space is already served by funded competitors.

AI Agent Permission and Code Scanner

Ingests AI agent configurations or GitHub repository URLs, analyzes them for overly broad permissions and malicious code, and returns a risk report.

Killed: no specific new capability, only a research theme

Smart LLM model router for engineering teams

A developer sends a prompt and task metadata, the software routes it to the cheapest model that can handle it, and returns the response with cost tracking.

Killed: The cluster is scattered AI industry news with no specific new capability, only one anecdotal pain point, and the proposed application is middleware that already exists as shipped products.

Enterprise Data Semantic Layer Generator

Users input their database schema and the software generates governed business definitions and context files for AI analytics tools.

Killed: The core functionality is rapidly being absorbed into native features of major data platforms like dbt and Snowflake, making a standalone application a temporary wrapper rather than a defensible product.

AI Search Visibility Tracker

Users input their brand and keywords, the software queries AI answer engines, and outputs a report on brand mentions and citations.

Killed: no specific new capability, only a research theme

Bug bounty report triage and quality scorer

A security team pastes or pipes in incoming bug bounty submissions and the software scores each report for quality, flags likely AI-generated or low-effort submissions, and outputs a ranked triage queue with recommendations to reject, investigate, or escalate.

Killed: No specific new capability is evidenced in the cluster; the supply signals describe new attack vectors and a platform's program restructuring, not a technology that enables a solution that was not possible before, and the market is already served by existing bug bounty platforms with built-in triage.

AI Agent Permission and Access Risk Scanner

A user uploads their AI agent tool definitions and configurations, the software maps what data and systems each agent can reach, and outputs a least-privilege risk report flagging over-permissioned agents.

Killed: No specific new capability, only a research theme. The supply signals are articles about intent-based access control and guardrails, not shipped products, released APIs, or published standards that make a new application buildable now.

MCP Gateway and Observability Proxy

Ingests MCP traffic from AI agents, traces multi-round-trip calls, and blocks security risks, returning sanitized requests and observability data.

Killed: The audience of developers actively deploying stateless MCP servers in production is too small and early to enumerate at scale, and the functionality will likely be absorbed by existing API gateways like Apigee.

Kill: Zimbra exploit and AI agent signals do not connect

No coherent application emerges because the anchor pain is a patched Zimbra webmail zero-day while the supply signals describe unrelated AI agent prompt injection and OAuth token abuse incidents.

Killed: The anchor pain (a patched Zimbra zero-day) and the supply signals (AI agent prompt injection and OAuth abuse incident reports) describe unrelated problems with no shared new capability, and neither half independently supports a buildable application.

Threat Advisory to Detection Rule Generator

Paste a threat advisory and the software extracts TTPs and IOCs, then outputs ready-to-deploy Sigma, YARA, and SIEM detection rules mapped to MITRE ATT&CK.

Killed: pain_evidence scored 5, floor is 6

Zimbra zero-click exploit indicator scanner

A user connects their Zimbra mail server logs or message store, the software scans for indicators of compromise associated with zero-click phishing campaigns, and returns a list of flagged messages and potentially compromised accounts.

Killed: The supply signals describe unrelated attack surfaces (AI coding agents, FFmpeg, GitHub prompt injection) with no connection to the Zimbra zero-click phishing pain, and the underlying vulnerability is already patched, so nothing is newly possible.

Kill: agentic AI infrastructure readiness is a theme not an app

The cluster describes an enterprise platform problem addressed by Google, HashiCorp and cloud providers, not a discrete application a solo developer can build.

Killed: No specific new capability, only a research theme; the pain is real but diffuse and enterprise-scale, with no discrete application loop a solo developer could build that existing platforms do not already cover.

Agentic AI infrastructure readiness scanner

User connects their cloud accounts and Kubernetes configs, the software evaluates them against agentic AI workload requirements, and outputs a readiness score with specific infrastructure gaps.

Killed: No specific new capability, only a research theme; pain is inferred from a vendor survey rather than stated by practitioners; the application collapses into a checklist with a cloud connection.

AI Agent Guardrail Tester

Ingests your AI agent's system prompt and tool definitions, runs automated red-teaming, and outputs a report of sandbox escape vulnerabilities.

Killed: no specific new capability, only a research theme

Open-weight model security scanner

Ingests a Hugging Face model URL and outputs a security and policy risk report for enterprise adoption.

Killed: no specific new capability, only a research theme

OAuth Token Scope Auditor for AI Integrations

A user connects their SaaS app tenant, the software scans all OAuth tokens granted to third-party AI agents and integrations, and it returns a ranked list of over-privileged or stale tokens to revoke.

Killed: No specific new capability in the supply signals, only a collection of unrelated security incidents and advisories; the cluster does not cohere around a single pain or a single new capability.

AI Sandbox Escape Detection Tool

Connects to AI agent environments to monitor and alert on autonomous sandbox escape attempts.

Killed: no specific new capability, only a research theme

Zimbra zero-click XSS payload scanner

Ingests email server logs and flags messages containing zero-click XSS payloads targeting Zimbra.

Killed: no specific new capability, only a research theme

Scan GitHub repos for AI agent prompt injection vectors

User connects a GitHub organization, the scanner analyzes repos, MCP server configs, and agentic workflow definitions for prompt injection vectors and malicious references, and returns a flagged risk report.

Killed: Pain is inferred from threat reports rather than evidenced by practitioners stating it, and the cluster conflates an already-patched email vulnerability with emerging AI agent security concerns.

AI Code Vulnerability Remediation Agent

Ingests a codebase, scans for vulnerabilities using AI, and outputs remediated code patches.

Killed: no specific new capability, only a research theme

AI Search Visibility Tracker for Agencies

Ingests a client brand and category prompts, queries major LLMs, and outputs a share-of-voice report for AI search.

Killed: no specific new capability, only a research theme

AI model cost router for engineering teams

Engineering teams connect their AI API usage and the software routes each request to the cheapest capable model, returning cost savings reports.

Killed: No specific new capability, only a research theme; model routing already exists as a product category and the pain is a single anecdote.

AI Agent Context Gap Scanner

Users input their data schema and agent prompts, and the software tests the agent's accuracy with and without context to output a hallucination risk report.

Killed: no specific new capability, only a research theme, and the pain is inferred from a vendor's internal eval rather than a buyer's stated problem.

AI Search Visibility Tracker

Users input their brand and target keywords, the software queries major AI answer engines, and outputs a report on mentions, citations, and share of voice.

Killed: no specific new capability, only a research theme

AI Bug Bounty Report Triage Filter

Ingests bug bounty submissions and flags AI-generated noise to prioritize real vulnerabilities.

Killed: The pain is being addressed by policy changes and existing platform triage rather than standalone software, and the audience is too small to enumerate.

AI Agent Permission and Action Auditor

A user connects their agent configurations and tool integrations, the software maps every action each agent can take across connected systems, and it returns a privilege heatmap flagging overprivileged agents and risky action paths.

Killed: The supply signals are thought leadership and research themes with no specific new capability, and the application requires deep system integrations that a solo builder cannot deliver at the level enterprises will demand.

AI Agent Prompt Injection and OAuth Scope Scanner

A user connects their AI agent integrations and the software tests them for indirect prompt injection susceptibility and overprivileged OAuth scopes, returning a vulnerability report.

Killed: The supply signals are incident reports and a research theme, not a specific new capability; the pain is inferred from news rather than stated by practitioners; and the audience cannot be enumerated without guessing at proxies for which companies use which AI agent platforms.

Threat Advisory to Detection Rule Generator

A user pastes a government threat advisory and the software parses out indicators, techniques, and affected systems to generate draft detection rules for their SIEM.

Killed: No specific new capability, only a research theme: the supply signals are thought leadership pieces and an article describing someone else's already-built system, not a released API, model, or standard that makes this newly buildable.

Zimbra Zero-Click Phishing Scanner

Ingests Zimbra mail logs and flags accounts targeted by zero-click phishing attempts.

Killed: no specific new capability, only a research theme

AI-Generated Infrastructure Code Security Scanner

Users upload Terraform or Kubernetes manifests, the scanner flags security flaws characteristic of AI-generated code, and returns a prioritized remediation list.

Killed: No specific new capability, only a research theme; existing static analysis tools already address the identified pain.

Agentic AI Infrastructure Readiness Scanner

A user connects their cloud account or uploads Kubernetes manifests, the software checks configuration against requirements for running agentic AI workloads, and it outputs a prioritized list of infrastructure gaps to fix.

Killed: No specific new capability, only a research theme; the pain is enterprise-scale infrastructure modernization that a solo developer cannot address with a small application, and the supply signals are blog posts and surveys rather than shipped capabilities.

AI Agent Permission and Intent Auditor

Users input their AI agent's system prompt and API permissions, and the software flags excessive privileges and potential escape vectors, outputting a least-privilege configuration report.

Killed: no specific new capability, only a research theme

Open-weight model policy tracker

A user inputs their AI model usage details and the software returns a compliance assessment against emerging open-weight regulations.

Killed: No specific new capability, only a policy lobbying theme with no enacted regulation and no practitioner-stated pain.

Mail server exposure checker for active threats

User inputs their mail server software and versions, software cross-references against active state-sponsored threat advisories and returns a prioritized exposure report.

Killed: No specific new capability in the supply signals, only news stories and a research paper; the proposed application is a commodity vulnerability scanner competing against entrenched products.

AI Agent Egress Firewall and Sandbox Monitor

Ingests network traffic logs from AI agent environments and blocks unauthorized outbound connections to prevent sandbox escapes.

Killed: no specific new capability, only a research theme

Zimbra compromise indicator scanner

A user uploads Zimbra mail server logs and the software checks them against known indicators of compromise from the Laundry Bear campaign and returns a report of likely compromised accounts and exfiltrated data windows.

Killed: No specific new capability connects the supply signals to the Zimbra zero-click pain; the vulnerability is already patched and the supply signals are unrelated security themes with no enabling technology for this application.

AI Agent Prompt Injection and Malicious Repo Scanner

A user connects their GitHub org and MCP server list, the software scans agent configurations and repository dependencies against known prompt injection patterns and malicious repo fingerprints, and returns a prioritized list of vulnerable agents and recommended fixes.

Killed: The anchor pain (Zimbra zero-click email theft) and the supply signals (AI agent prompt injection, malicious repos) are different problems for different people with no connecting capability, and the supply signals are threat reports rather than a specific new capability.

Kill: no application emerges from policy news

No coherent software loop can be derived from these signals; they are news coverage of a government visa policy plus loosely related academic surveys.

Killed: No specific new capability, only policy announcements and academic themes; no identifiable software-buying audience experiences an expressed pain that an application could address.

Kill: no specific new capability, only research themes

The cluster pairs a real pain (ransomware via compromised logins) with supply signals that are blog posts and research themes about AI in security, not a shipped capability, API, or standard that makes a new application buildable.

Killed: No specific new capability, only a research theme; the pain is real but the supply signals are blog posts about AI in security, not a released model, API, or standard that makes a new application buildable, and the application space is dominated by entrenched incumbents.

AI Agent Scaffolding and Evaluation Platform

Developers input a plain English description of an agent, and the software generates, tests, and deploys the agent code.

Killed: The pain is inferred from vendor announcements rather than stated by users, and the signals are platform features rather than a new capability a solo developer can exploit.

AI Pull Request Triage and Vulnerability Scanner

A user connects a GitHub repository, and the software scans incoming AI-generated pull requests to flag vulnerabilities and policy violations, returning a prioritized review queue.

Killed: The core capability is already being shipped by enterprise vendors (Google, Black Duck), and the remaining signals describe policy and governance needs rather than a defensible buildable application niche for a solo developer.

AI Search Visibility Tracker

Users input their brand and target prompts, the software queries major LLMs, and outputs a dashboard of brand mentions and positioning over time.

Killed: no specific new capability, only a research theme

MCP Server and AI Skill Repo Security Scanner

A developer or security engineer pastes a GitHub repo URL or MCP server config, the tool analyzes it for malicious patterns and excessive permissions, and returns a risk score with specific findings.

Killed: Pain is inferred from news stories about threats, not expressed by identifiable people who need this tool, and the specific audience responsible for AI agent supply chain security cannot be sharply enumerated.

AI model router for cost-aware engineering teams

A developer sends a prompt, the software classifies the task and routes it to the cheapest model that can handle it, and returns the response with cost tracking.

Killed: The cluster is noise: the anchor pain about Meta's consumer AI assistant does not connect to the supply signals about enterprise AI infrastructure, no specific new capability is identified, and the only stated pain is a single person's wish for a feature that platform providers are already building.

Enterprise AI Context Generator and Accuracy Evaluator

You upload your data warehouse schema and business glossary, the software generates structured context packages for AI agents and runs an eval suite showing accuracy with and without that context, and you get a deployable context file plus an accuracy gap report.

Killed: No specific new capability that makes this buildable now and not before; the supply signals are research themes and one narrow platform integration, and any application would compete with data platform vendors already building semantic layers and AI context into their products.

Scanner for Malicious AI Model Artifacts

Users submit a Hugging Face model or dataset URL, the software scans the artifact for malicious code, data poisoning, and suspicious execution patterns, and returns a security risk report.

Killed: Pain is inferred from a single news event rather than stated by practitioners, and existing open-source tools already scan ML model artifacts for malicious code.

AI Search Visibility Tracker

Users input their brand name and target keywords, the software queries major AI search engines with relevant prompts, and outputs a dashboard tracking brand mentions, citations, and share of voice over time.

Killed: no specific new capability, only a research theme

Bug bounty report triage and AI-noise filter

A bug bounty program manager pastes or pipes in submissions and the software scores each report for likelihood of being AI-generated noise versus a genuine finding, returning a ranked triage queue.

Killed: The evidenced pain was solved by the sufferer through policy changes rather than software, the newly possible signals name a new problem but no new detection capability, and the audience is a small cross-referenced population whose pain is inferred rather than stated beyond a single company.

AI Agent Access Scope and Blast Radius Auditor

Upload your AI agent's MCP configuration and tool definitions, and it maps every system the agent can reach, flags overprivileged access, and outputs a prioritized remediation report.

Killed: The audience actually deploying production AI agents with real system access is too small and early to support a product, and the supply signals are thought leadership about an emerging theme rather than specific new capabilities.

Threat Advisory to Detection Rule Generator

Ingests a threat advisory URL and outputs ready-to-use SIEM detection rules.

Killed: no specific new capability, only a research theme, and pain is inferred rather than evidenced.

AI-Generated Infrastructure Code Security Scanner

User connects a Git repo or uploads Terraform and Kubernetes manifests, the software scans for security gaps characteristic of AI-generated infrastructure code, and returns a prioritized list of unsafe configurations with remediation steps.

Killed: No specific new capability, only a research theme: the supply signals are trend reports and vendor blog posts, and the underlying scanning capability already exists in mature open-source and commercial tools.

Agentic AI Infrastructure Readiness Scanner

User uploads Kubernetes manifests and cloud infrastructure config, the software checks them against agentic AI workload readiness criteria, and outputs a prioritized gap report.

Killed: No specific new capability, only a research theme; the supply signals are blog posts and surveys restating that agentic AI needs infrastructure upgrades, with no released API, model, or published standard that enables a concrete application.

AI Agent Intent Access Controller

Ingests agent action logs and flags actions that deviate from declared intents.

Killed: no specific new capability, only a research theme

Open-weight AI policy compliance scanner

A compliance officer inputs an open-weight model identifier and the tool returns a risk and regulatory exposure assessment based on current US policy signals.

Killed: The cluster is a policy lobbying debate with no evidenced operational pain and no specific new capability, only restatements of an advocacy theme.

AI Agent Prompt Injection Scanner

Users input a GitHub repository or issue URL, and the software scans for hidden prompt injection payloads designed to exploit AI coding agents, returning a risk report.

Killed: The cluster is a coincidence of unrelated cybersecurity news; the anchor pain (Zimbra email exploit) has no connection to the supply signals (AI agent prompt injection).

Zimbra Zero-Click XSS Compromise Scanner

Ingests Zimbra server logs and outputs a report of potential Laundry Bear zero-click XSS compromises.

Killed: no specific new capability, only a research theme

IOC Scanner for AI Agent Supply Chain Attacks

Ingests your GitHub and OAuth integration lists, cross-references them against recent state-sponsored attack indicators, and flags compromised assets.

Killed: no specific new capability, only news of attacks and an unrelated academic article.

AI Agent Sandbox Escape Detector

Routes AI agent network traffic through a proxy that analyzes actions and blocks sandbox escape attempts.

Killed: pain is inferred from a news story and no specific new capability, only a research theme

GitHub AI Agent Prompt Injection Scanner

A user inputs a GitHub organization name, and the software scans issues and repositories for hidden prompt injection payloads targeting AI coding agents, returning a report of malicious instructions.

Killed: pain is inferred from news stories of attacks, not evidenced by a practitioner stating the pain in their own words

The gates each one had to clear

Is it software
A running loop with inputs and outputs, not a document product.
Reachable audience
How many individually identifiable people could be reached about it within weeks.
Evidenced pain
Somebody stated it in their own words, or a regulator set a dated obligation. Inferred pain fails.
Findable audience
Specific enough to search for by role and sector.
Newly possible
A capability that did not exist last year. Recency is not novelty, and a research theme is not a capability.

An idea dies on the first gate it misses. Most die on the last one.

The corpus behind the judgement

723 compliance frameworks, 20,473 controls, 332,959 cross-framework mappings, 531 frameworks verified against source documents.

See the corpus