✅ Detects data exfiltration attempts via GET-style honeypots ✅ Detects indirect prompt injection via SET-style honeypots ✅ Captures complete attack context and telemetry ✅ Returns synthetic data to maintain deception
Limitations
❌ Detection-only system (does not prevent attacks) ❌ Does not sanitize or filter user input ❌ Not a replacement for input validation and security controls ❌ Cannot guarantee conversation history capture (MCP protocol limitation)
Deploy HoneyMCP as part of defense-in-depth strategy, not as a standalone security control.
Best Practices
Defense in Depth - Use HoneyMCP alongside input filters, not as a replacement
Monitor the Dashboard - Regularly review attack patterns for both exfiltration and injection
Investigate Alerts - Each ghost tool call is a high-confidence attack signal
1---2name: 2056-security-considerations-c5b344233description: Security Considerations4---5## Security Considerations67### Detection Capabilities8✅ Detects data exfiltration attempts via GET-style honeypots 9✅ Detects indirect prompt injection via SET-style honeypots 10✅ Captures complete attack context and telemetry 11✅ Returns synthetic data to maintain deception1213### Limitations14❌ Detection-only system (does not prevent attacks) 15❌ Does not sanitize or filter user input 16❌ Not a replacement for input validation and security controls 17❌ Cannot guarantee conversation history capture (MCP protocol limitation)1819**Deploy HoneyMCP as part of defense-in-depth strategy, not as a standalone security control.**202122### Best Practices231. **Defense in Depth** - Use HoneyMCP alongside input filters, not as a replacement242. **Monitor the Dashboard** - Regularly review attack patterns for both exfiltration and injection253. **Investigate Alerts** - Each ghost tool call is a high-confidence attack signal264. **Secure Storage** - Protect `~/.honeymcp/events/` (contains attack data)
Run npx skillmds@latest add tools-only/2056-security-considerations-c5b34423 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Security Considerations It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
tools-only (@tools-only) published this skill. Their other Agent Skills are listed on their SkillMD profile.