# Lovable — How we run swarms of AI hacking agents against ourselves in a game of capture the flag

- Company: Lovable (lovable.dev)
- Announced: 2026-07-24T14:30:00+00:00
- Category: not stated
- Coverage: not counted
- Announcement: no
- Group: routine
- Source: https://lovable.dev/blog/how-we-run-swarms-of-ai-hacking-agents-against-ourselves
- Record: https://forck.live/items/12068-how-we-run-swarms-of-ai-hacking-agents-against-ourselves-in-a-game-of-capture
- Subject: Lovable / AI app builder

Lovable describes its internal offensive security program that uses swarms of AI agents to probe its infrastructure for vulnerabilities. Agents must capture a flag—a string from an inaccessible system—as deterministic proof of a real vulnerability, not a model's guess. The program does not replace human security researchers; agents still require human coordination and understanding.

## Evidence

Verbatim from https://lovable.dev/blog/how-we-run-swarms-of-ai-hacking-agents-against-ourselves:

> We don't take an agent's word for anything. We make it prove its work by retrieving a flag, a special string of text, from a system it should never have been able to reach. The flag is ground truth. A capture is deterministic proof of a real vulnerability, not a model's hunch that something looks exploitable.

---

Record: https://forck.live/items/12068-how-we-run-swarms-of-ai-hacking-agents-against-ourselves-in-a-game-of-capture
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
