Tool · curated 11 Aug 2026

GitHub - barvhaim/HoneyMCP: A Deception Security Layer for MCP Servers. It injects "ghost tools" (fake security-sensitive tools) that act as honeypots.

Coverage timeline

11 Aug 2026github.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

HoneyMCP gives defenders a detection mechanism for malicious or hijacked AI agents abusing MCP tool-calling, an emerging attack surface with little native monitoring.

HoneyMCP is an open-source deception security layer for MCP (Model Context Protocol) servers that injects fake security-sensitive "ghost tools" acting as honeypots. When an agent or attacker invokes one of these decoy tools, the activity is flagged as suspicious and surfaced in a SOC-style dashboard, helping defenders detect malicious or compromised AI agents interacting with MCP servers.