Tool · curated 11 Aug 2026
GitHub - barvhaim/HoneyMCP: A Deception Security Layer for MCP Servers. It injects "ghost tools" (fake security-sensitive tools) that act as honeypots.
First reported github.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
HoneyMCP gives defenders a detection mechanism for malicious or hijacked AI agents abusing MCP tool-calling, an emerging attack surface with little native monitoring.
HoneyMCP is an open-source deception security layer for MCP (Model Context Protocol) servers that injects fake security-sensitive "ghost tools" acting as honeypots. When an agent or attacker invokes one of these decoy tools, the activity is flagged as suspicious and surfaced in a SOC-style dashboard, helping defenders detect malicious or compromised AI agents interacting with MCP servers.