HoneyTrap Enterprise AI Agent Security
Paste the following prompt into your AI chat to install this skill:
Follow https://skillhub.cn/install/skillhub.md to install @user_0990763f/honeytrap.
About this skill
Problem
When a local AI Agent is reachable by external tools, crawlers, or other Agents, sensitive files, credentials, API configs, and conversation context can be exposed. Traditional endpoint security relies on signatures, behavior monitoring, and automated response; Agent systems also need defenses for prompt injection, memory poisoning, tool abuse, and impersonation. HoneyTrap treats these interactions as security events rather than ordinary tool calls.
How It Works
The skill is organized around detection, response, and forensics:
- Attack fingerprinting: identifies patterns such as curl, scrapy, external Agent markers, and prompt-injection structures, then assigns risk levels.
- Counter-response: selects honeypot payloads, fake endpoints, fake keys, rejection, or delay traps from 100ms to 5000ms.
- AV defense engine: borrows AV and EDR/XDR ideas, using fingerprint libraries, behavior monitoring, heuristic rules, automated response playbooks, threat intel, and forensic reports.
- Self-protection and IP control: uses HMAC-SHA256 integrity checks, an Owner Key permission model, IP allow/deny lists, rate limiting, and owner confirmation to reduce unauthorized access and tampering.
Boundaries
It is better suited to protecting a local or private Agent’s sensitive context. It is not for deceiving real users or malicious activity. Honeypot content, webhook alerts, auto-bans, and audit logs must be configured for the deployment; losing the developer key can block unlocking and updates.
Use Cases
- Intercept bulk reads of `.env` and fake API calls when local Agents expose external tools
- Reject prompt-injection attempts, alert the owner, and generate forensic reports for Agent sessions
- Manage a private Agent service with IP allowlists, rate limits, and automatic bans for suspicious sources
- Protect skill files from tampering by other skills using Owner Key verification and integrity checks
Best For
- Security engineers maintaining local AI Agents who need prompt-injection detection and audit logs
- Platform engineers deploying private Agent services who need IP allowlists, bans, and rate monitoring
- Developers building multi-skill workspaces who need to prevent other skills from tampering with configs
- Ops owners of sensitive knowledge bases who need to block bulk reads of `.env` and credential files
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
A pre-release security auditor for Skills that statically checks injection, credentials, SSRF, CVEs, and permissions, with scored reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.