What it does
An open-source deception framework that lets you deploy decoy services and record how they are used. It can build decoy MCP tools that an agent would never call in normal work, so any use of them points to prompt injection or malicious agent behavior. Services and responses are defined in YAML.
Use cases
- 01Add decoy MCP tools to spot prompt injection attempts
- 02Record what an attacker does against a fake service
- 03Collect interaction logs as evidence for an investigation