HoneyCrawlPot Tricks AI Vulnerability Scanners with Fake Credentials and Prompt Traps
HoneyCrawlPot is an open-source middleware tool designed to deceive AI-powered vulnerability scanners that probe APIs for sensitive files like .env and AWS credentials. Instead of returning a standard 404 error, it serves a convincing fake file containing inert credentials, prompt-injection payloads, and a unique canary token. The prompt injections target LLM-based scanning agents, attempting to waste their token budgets, corrupt their reports, or trick them into marking a host as safe. The canary token allows developers to detect when a scanner has consumed the decoy, providing visibility into who is probing their systems. The tool requires no external dependencies and is compatible with both Hono and Express frameworks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in