Don't know what to build?

Constellate analyzes ideas from 9 leading tech sources and finds what's missing—real gaps where something could exist but doesn't.

gaps detected
40
gaps detected
ideas analyzed
1,643
ideas analyzed
sources
9
sources

Latest analysis: Jul 31, 2026

See current gaps ↓

Follow future releases

Follow on GitHub

Weekly digest coming soon. No email form is active yet.

Top Gaps — latest analysis

Where something could exist but doesn't

Showing the top 12 of 40 gaps detected across 1,643 ideas. Each gap is a real pattern of absence — a logical piece the community keeps circling without naming.

Gap detected

A Blast-Radius Firewall for Coding Agents

We have the symptom (agent modifies three pages outside its spec), the theory (agents need FSM-style constraints), the consequence (silent pipeline failures, AI-generated legacy code), and the audit failure (gates that don't catch sequences). What's absent is the obvious product: a tool that enforces a declared scope on agent edits — file allowlists, diff-radius limits, automatic rejection of out-of-spec changes at commit time. Every idea here circles the need for externally enforced boundaries, yet none builds the enforcement layer itself. It's a bounded, shippable wedge into the agent-reliability market.

Gap detected

Everyone builds agents; nobody builds agent identity

This neighborhood contains agent protocols (3698), agentic workflows (3738), agent orchestration (3743), a secret scanner for humans' mistakes (3739), and a tunnel client for secure access (3737). What's structurally missing is the piece all of these imply: credential and identity management for autonomous agents — scoped, revocable, auditable secrets that agents can use without leaking them. Gitleaks catches human-committed secrets; nothing here prevents an agent with workflow permissions from exfiltrating or misusing them. Given agents now run CI, manage cloud resources, and open tunnels, the missing 'vault for agents' is the most dangerous gap in the set.

Gap detected

Skills Get Made and Listed, Never Tested

This neighborhood has a full skill supply chain: automated generation from books (3673), industrial prompt-template mining (3711), packaging into agent runtimes via MCP (5151), and curation lists (3685). What's structurally missing is the quality layer: nothing here evaluates, benchmarks, or certifies whether a skill actually works, is safe, or degrades across model versions. As skills become distributable artifacts, an 'npm audit / CI for agent skills' is the obvious gap that lists alone can't fill.

Gap detected

A CI/CD Certification Suite for Agent Skills

The neighborhood contains skill-use verification (4572), skill compilation (4627), blind-spot discovery (4605), readiness philosophy (4492), and a production benchmark (4155) — but no tooling that ties them into a developer workflow. What's absent is a 'pytest for agent skills': a CI harness that runs counterfactual ablations, checks that skills causally alter decisions, enforces typed control flow, and gates deployment on readiness metrics. Every ingredient exists as research; nobody has shipped the practitioner tool. This is the obvious productization gap for the emerging skills ecosystem (MCP SDK 3699/3700 shows the distribution channel already exists).

Gap detected

mission control for swarms of local agents

Goose runs autonomous agents, worktrunk manages git worktrees explicitly for parallel agent workflows, jcode optimizes the harness for RAM efficiency, and Vector pipes observability data at scale — yet nothing here watches, compares, or arbitrates between the parallel agents these tools clearly anticipate. The gap is an agent-fleet observability and orchestration layer: which of my 8 concurrent agent branches is winning, what did each cost, when should one be killed. Every piece of the substrate exists; the cockpit doesn't.

Gap detected

Nobody evaluates whether agent memory is worth keeping

The neighborhood is dense with memory mechanisms — reconstruction (4253), contribution scoring (4304), episodic-to-parametric transfer (5016), self-distillation (4380), and harness evolution (4843) — but contains no benchmark or tooling that measures memory quality itself: contamination, staleness, negative transfer, or when accumulated experience actively hurts. Trace-level agent eval exists, but nothing audits the memory layer as a first-class artifact. The missing piece is a memory observability/eval suite: given an agent's memory store, quantify which entries help, hurt, or have decayed. Every team building long-lived agents needs this and currently ships blind.

Gap detected

security-grade observability for MCP agent traffic

The neighborhood contains an agent intrusion post-mortem (3922), agent telemetry that shocked its own builders (5223), and a major MCP spec change to stateless transport (3989, 5225) that makes session-level auditing harder, not easier. What's structurally missing is the piece these four imply: an audit/anomaly-detection layer purpose-built for stateless MCP traffic — a 'flight recorder' for agent-tool interactions. Everyone here is either migrating the protocol or cleaning up after incidents; nobody is building the middle layer that would prevent the next timeline post.

Gap detected

No one monetizes backendless software

The neighborhood contains fully client-side apps (5232, 5288) and self-hosted commerce/payment stacks that all assume a PHP server (3803, 3807). What's missing is the bridge: a monetization/licensing layer for zero-backend software — selling license keys, unlocks, or subscriptions for apps that have no server to validate against. The backendless builders explicitly avoid servers, while the payment tools require them, leaving indie devs of local-first tools with no native way to charge. A lightweight license-key + edge-verification service for client-side apps and extensions is the obvious gap.

Gap detected

a red-team benchmark for agent security

The neighborhood has agent governance tooling (3678), real breach post-mortems (5153), a personal attack suite that broke its own defenses (5239), a general agent evaluation framework (3681), and a culture of pre-registered benchmarks (5266). What's conspicuously absent is the connective piece: a standardized, reproducible adversarial benchmark that scores agent deployments against sequence-composition and privilege-escalation attacks the way OWASP scores web apps. Everyone here is either defending, attacking, or evaluating—nobody has productized the attack-eval loop.

Gap detected

CI for Agent Behavior, Not Model Outputs

The neighborhood has execution-failure evidence (4277), a benchmark (4609), training environments (4327), and testing techniques battling flakiness (5116, 5285) — but no continuous, developer-facing tool that runs agents through realistic stateful scenarios on every model or prompt change and flags execution-layer regressions. Everyone diagnoses the gap between static metrics and agentic behavior; nobody in this set ships the 'pytest for agents' that closes it. Given the pieces already exist (env generation, semantic UI hooks, fault taxonomies), the missing artifact is an integration layer, not new research.

Gap detected

Companion AI Has No Wellbeing Monitor

This neighborhood contains self-hosted AI companions (3687), evaluation of role-play agents for emotional comfort (4433), voice-based psychotherapy training (5125), and speech biomarkers for depression (5060). The missing piece is obvious once laid out: a passive layer that applies clinical speech-biomarker detection inside companion/role-play conversations to flag deteriorating user mental health and adapt or escalate. Everything needed exists — the intimate voice channel, the eval frameworks, the biomarkers — but no one has connected companion AI to actual wellbeing signals rather than engagement metrics.

Gap detected

The On-Device Mobile Agent Runtime

This neighborhood has agent languages, agent protocols, JVM agent frameworks, and AI assistants embedded in desktop tools (Xcode, macOS video editing). It also has a dense cluster of native iOS/Android apps. Yet nothing bridges them: there is no native, privacy-first agent runtime that runs on the phone itself, the way Harper does grammar checking offline. Given the local-first ethos of the surrounding projects (Harper, Bitwarden, UTM), an on-device Swift/Kotlin agent host implementing the agent-host-protocol is the obvious missing piece.

How it works

1

We analyze 9 leading tech sources

Hacker News, arXiv, Y Combinator, Product Hunt, GitHub Trending, Hugging Face, Dev.to, BetaList, Papers With Code. You never have to add a source.

2

Claude clusters and reasons over groups

Instead of comparing items in pairs, Constellate asks Claude to look at groups of 3-6 ideas and find what they collectively imply.

3

Absences surface as real gaps

When a group of ideas keeps circling a problem without anyone naming the missing piece, that piece shows up here — as something you could build.

Follow the next data release

The date above identifies the latest manually published snapshot. Follow the repository to see when the next verified release is available.

Follow on GitHub

Weekly digest coming soon. No email form is active yet.