Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add GoldenWing-360/claude-security-skills --skill honeypot-tarpitsgit clone --depth 1 https://github.com/GoldenWing-360/claude-security-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/goldenwing-360/claude-security-skills/honeypot-tarpits)<a href="https://agentmods.dev/skills/goldenwing-360/claude-security-skills/honeypot-tarpits"><img src="https://agentmods.dev/badge/skills/goldenwing-360/claude-security-skills/honeypot-tarpits/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/goldenwing-360/claude-security-skills/honeypot-tarpits"><img src="https://agentmods.dev/badge/skills/goldenwing-360/claude-security-skills/honeypot-tarpits.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00082 | $0.02358 |
| Opus 5 | $0.00041 | $0.01179 |
| Sonnet 5 | $0.00016 | $0.00472 |
| Haiku 4.5 | $0.00008 | $0.00236 |
Grade A, and why
honeypot-tarpits scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 210 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Honeypots and Tarpits
A honeypot is a resource that exists only to be hit by attackers. Anyone who interacts with it is, by definition, doing something they should not be. That makes honeypots one of the highest-signal detection mechanisms available — almost zero false positives, and trivial to operate at small scale.
This skill covers practical, low-effort patterns for solo operators and small teams. Not enterprise deception platforms (Thinkst Canary, etc., are excellent if you can afford them — but the same ideas work DIY).
When to invoke
- Public services see constant automated probing (fail2ban catches most but you want better signal)
- You want detection without a full SIEM
- Complementing existing WAF rules
- After reconnaissance against a specific service (set traps for the next scan)
- You want early warning if a credential leaked (canary tokens)
Honeypot pattern 1 — fake admin paths
Common scanner targets — /wp-admin/, /administrator/, /manager/, /phpmyadmin/, /.git/config — are reliable signals of automated probing. If you serve a real-looking 200 response and capture the source, you have an attacker IP/UA before they reach anything real.
# nginx — fake admin endpoint
location ~ ^/(wp-admin|administrator|phpmyadmin|manager/html|.git/config|.env)$ {
access_log /var/log/nginx/honeypot.log honeypot_fmt;
add_header Content-Type text/plain;
return 200 "OK"; # Looks fake, but the goal is the log entry, not realism
}
# Optional: in a separate http block, structured logging
log_format honeypot_fmt escape=json '{'
'"time":"$time_iso8601",'
'"ip":"$remote_addr",'
'"path":"$request_uri",'
'"method":"$request_method",'
'"ua":"$http_user_agent",'
'"referer":"$http_referer"'
'}';
Pipe /var/log/nginx/honeypot.log to your alerting (Loki + Grafana alert, Better Stack, a tiny daemon that pings a webhook). Every hit is an attacker.
Optional escalation: feed honeypot-hit IPs straight to fail2ban or Cloudflare WAF block.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 210 lines · 82 tokens per session scan A 3d341587fbd3
honeypot-tarpits is a skill published in the GitHub repository GoldenWing-360/claude-security-skills (17 stars, last pushed 1mo ago), licensed MIT. It adds 82 tokens to every session and 2,358 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ux-audit
Walk through a live web app AS a real user to find usability + behavioural bugs that static reviews miss. REQUIRES proof of interaction (typing, clicking, sending, observing) before any verdict — a sweep that didn't interact terminates with verdict 'Incomplete'. Walks threads, exercises every element, runs the…
design-loop
Autonomous multi-page site builder using a baton-passing loop. Each iteration reads a task from .design/next-prompt.md, generates a page in HTML/Tailwind, integrates it into the site, verifies visually, then writes the next task to keep the loop alive. Use whenever the user asks to build an entire site autonomously…
product-showcase
Generate a comprehensive marketing website for a web app — multi-page with real screenshots, animated GIF walkthroughs, feature deep-dives, and workflow demonstrations. Browses the running app, captures screens and sequences, and produces a deployable site that actually teaches people what the product does. Especially…
tanstack-start
Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 +…
color-palette
Generate complete, accessible colour palettes from a single brand hex. Produces 11-shade scale (50-950), semantic tokens, dark mode variants, Tailwind v4 CSS output, WCAG contrast checks. Use whenever the user supplies a brand hex and asks for a palette, mentions setting up a design system, wants Tailwind theme…
deep-research
Deep research and discovery before building something new. Explores local projects for reusable code, researches competitors, reads forums and reviews, analyses plugin ecosystems, investigates technical options, and produces a comprehensive research brief. Three depths: focused (30 min), wide (1-2 hours), deep (3-6…