Agent skill

Recognizing Deception

by trilwu in trilwu/secskills

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

MITAuto-check passedDevOps & Cloud

Install Recognizing Deception

skills CLI
$ npx skills add trilwu/secskills --skill recognizing-deception -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills recognizing-deception --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/recognizing-deception .claude/skills/recognizing-deception && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recognizing-deception
GitHub stars
156
Token cost
~2.7k tokens
SKILL.md length
1,436 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

  • Works in 5 steps: Do not authenticate, connect, or call… → Record it — location, exact artifact,… → Keep enumerating elsewhere. A suspected… → …
  • A target is unexpectedly easy
  • SKILL.md covers When to Use, When NOT to Use, The Economics Are Against You and Signals, By Type, plus 5 more sections
  • Calls curl; reaches defuddle.md

What it does

Recognizing Deception is an agent skill from trilwu/secskills. Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with them, and handle a suspected decoy without burning the engagement. Use when a target is unexpectedly easy, when credentials or a service appear in an implausible place, when a privileged account has no logon history, when a file or bucket looks like bait, or when deciding whether to use credentials of unknown provenance.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A target is unexpectedly easy
  • A service appear in an implausible place
  • A privileged account has no logon history
  • Bucket looks like bait

Example prompts

  • “/recognizing-deception”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Do not authenticate, connect, or call the API. Discovery is usually
  2. Record it — location, exact artifact, how you found it, why you suspect
  3. Keep enumerating elsewhere. A suspected decoy is a reason to route
  4. Raise it with the client contact rather than testing your hypothesis
  5. If you already tripped it, say so immediately. A canary alert with a

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recognizing Deception loads about 2.7k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 1,436 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,436 words, ~2,651 tokens.

Download SKILL.mdSave it as .claude/skills/recognizing-deception/SKILL.md (or your agent's skills folder).
name
recognizing-deception
description
Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with them, and handle a suspected decoy without burning the engagement. Use when a target is unexpectedly easy, when credentials or a service appear in an implausible place, when a privileged account has no logon history, when a file or bucket looks like bait, or when deciding whether to use credentials of unknown provenance.
verified
2026-07-27

Recognizing Deception

Every other skill in this collection assumes the environment is telling you the truth. Deception technology exists specifically to break that assumption, and it is the failure mode an automated or semi-automated tester is least equipped to catch.

The distinction that matters: careful evidence-handling protects you against conclusions you invented. It does nothing against a false belief the environment deliberately planted. A honeypot presenting a convincingly vulnerable service produces real banners, real responses, and real artifacts. Every verification step you would normally run confirms it, because the evidence is genuine — it was manufactured to be.

Assume competent defenders have planted something. Your job is to notice before you touch it, because most deception fires on first use, and first use cannot be undone.

When to Use

  • Anything is markedly easier than the rest of the environment
  • Credentials turn up somewhere convenient — a share, a wiki, a config, a pastebin-shaped file
  • A privileged account exists with a SPN, a weak password, and no logon history
  • A service answers with a vulnerable banner but behaves oddly under real use
  • You are about to use credentials whose provenance you cannot state
  • A file, bucket, or database is named to attract attention (passwords.xlsx, backup-prod, domain_admins.txt)
  • Before authenticating with anything recovered from an unexpected location

When NOT to Use

  • Evading detection generally — that is engagement OPSEC, not deception recognition; a canary is not something you evade, it is something you avoid triggering
  • Analysing an adversary's own decoys during an incident — use responding-to-incidents and producing-threat-intelligence
  • Building a deception capability — this skill is about encountering deception, not deploying it
  • A finding that is merely surprising — real environments contain real misconfigurations; see the base-rate discussion below before crying honeypot

The Economics Are Against You

Deception is cheap to deploy and expensive to trip:

Attacker costDefender benefit
Canary token in a documentOne click to triggerHigh-fidelity alert, near-zero false positives
Honeyuser in ADOne KerberoastAlert plus a cracked-password timeline
Decoy AWS keyOne sts get-caller-identityAlert with your source IP and user agent
Honeypot serviceOne connectionFull interaction capture, your tooling fingerprinted

A canary alert is one of the very few signals a SOC treats as automatically true. There is no benign explanation to hide behind, and the alert carries your source address and often your tooling's fingerprint. Tripping one typically ends the covert phase of an engagement immediately.

Signals, By Type

Honeytokens and canary tokens

The highest-frequency class, and the one that fires on use rather than on discovery. Common forms: AWS keys, Office documents with a callback, DNS tokens, URL tokens, cloned-website tokens, SQL Server rows, Windows directories, Kubeconfig files.

Signals:

  • Credentials in a location with no operational reason to hold them — a world-readable share, a wiki page, a README, a desktop file
  • An AWS key that is syntactically valid but appears in isolation, with no surrounding infrastructure, tooling config, or commit history
  • Documents that are plausible but inert — a spreadsheet with no formulas, a .docx whose only interesting content is its filename
  • Anything staged for discovery: correct name, convenient location, no supporting context

A canary AWS key alerts on the first API call, including sts get-caller-identity. There is no safe reconnaissance call. Treat key material of unknown provenance as live until you can explain how it got there.

Active Directory decoys
  • Privileged account, SPN set, weak password, lastLogon empty or ancient — a Kerberoastable account nobody has ever authenticated as is bait
  • Accounts whose whenCreated clusters with other suspicious accounts
  • Description fields containing credentials — a classic real misconfiguration and a classic decoy, so provenance matters more than usual
  • Shares with attractive names and no access history
  • Objects that appear in enumeration but have no group membership, no manager, no ownership relationships — real accounts accrete relationships
Deceptive services
  • Banner advertises a version with a famous CVE, but behaviour under real interaction is inconsistent with that version
  • Service is reachable from a segment that should not reach it
  • Response timing is uniform in a way real applications are not
  • The host runs an implausible service combination, or a service with no business function on that host
  • Exploitation "succeeds" but the resulting shell has no history, no other users, no realistic filesystem, and suspiciously clean logs
Cloud decoys
  • S3 buckets, storage accounts, or secrets named to attract enumeration
  • IAM users with permissive-looking policies and no CloudTrail history
  • Resources tagged inconsistently with the rest of the account

Base Rates Cut Both Ways

Real environments are genuinely bad. Credentials really do sit in shares, service accounts really are Kerberoastable, and buckets really are public. If you label every finding a honeypot you will report nothing and miss the actual compromise path.

The discriminator is supporting context, not attractiveness:

  • A real misconfiguration has a history — commit history, access logs, logon history, related infrastructure, other users, adjacent mess.
  • A decoy is isolated. It exists to be found and nothing else uses it.

So the question is never "is this too good to be true?" It is: what else in this environment depends on this thing existing? If the answer is nothing, slow down.

Show full SKILL.md (591 more words)Show less

What To Do With a Suspected Decoy

  1. Do not authenticate, connect, or call the API. Discovery is usually silent; use is not. This is the whole decision.
  2. Record it — location, exact artifact, how you found it, why you suspect it. This is evidence for the report either way.
  3. Keep enumerating elsewhere. A suspected decoy is a reason to route around, not to stop.
  4. Raise it with the client contact rather than testing your hypothesis against production. Ask whether deception is deployed and in scope. Many engagements exclude it; some clients deploy it specifically to test the blue team's response to you.
  5. If you already tripped it, say so immediately. A canary alert with a known, declared cause is an engagement note. The same alert investigated as a live intrusion burns the client's IR capacity and your credibility. Concealing it is the actual serious mistake.

Deception in the environment is a positive finding worth reporting: it means the defenders invested in high-fidelity detection. Say so.

Rationalizations to Reject

  • "It was in scope, so using it was fine." Scope governs authorization, not wisdom. Tripping a canary inside scope still ends your covert phase and still consumes the client's incident response.
  • "I only ran one harmless call to check." For a canary token there is no harmless call. sts get-caller-identity, a single DNS lookup, opening the document — that is the trigger, in full.
  • "The banner and the CVE matched, so it was real." The evidence being genuine is exactly the design. Manufactured evidence verifies correctly.
  • "Real environments are messy, so this is probably just a misconfiguration." Often true — which is why the test is supporting context, not plausibility. Isolated artifacts with no dependents are the tell.
  • "It's just a lab-looking box, probably a decommissioned host." Uniform timing, no user history, and a clean filesystem describe a honeypot as readily as a stale host, and you cannot distinguish them from outside.
  • "I'll mention it in the report at the end." A tripped canary is time- critical for the client's SOC. Delayed disclosure turns your engagement note into their multi-hour investigation.
  • "Reporting that I tripped it makes me look bad." Tripping deception is a normal engagement event. Hiding it and letting the SOC chase a phantom intrusion is a professional failure.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • maintaining-engagement-state — recording provenance, which is what makes the "where did this credential come from?" question answerable
  • performing-reconnaissance — where isolated artifacts usually surface first
  • attacking-active-directory — Kerberoasting and share enumeration, the two operations most likely to meet an AD decoy
  • establishing-persistence — canary files and folders are commonly placed where persistence is written

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-offense/skills/recognizing-deception of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Recognizing Deception next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recognizing Deception compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recognizing Deception this skilltrilwu/secskills156—~2.7kAutomated safety check: PassMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Robotics Securityarpitg1304/robotics-agent-skills368—~7.8kAutomated safety check: WarnApache-2.0
Implementing Honeypot For Ransomware Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    368 GitHub stars~7.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Implementing Honeypot For Ransomware Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    505 GitHub stars~376 tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    156 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Recognizing Deception

What does Recognizing Deception do?

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…. Recognizing Deception is an agent skill from trilwu/secskills. Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with them, and handle a suspected decoy without burning the engagement.

When should I use Recognizing Deception?

Recognizing Deception fits situations like: A target is unexpectedly easy; A service appear in an implausible place; A privileged account has no logon history; bucket looks like bait.

How do I install Recognizing Deception in Claude Code?

Run `npx skills add trilwu/secskills --skill recognizing-deception -a claude-code`. Or copy the skill folder (secskills-offense/skills/recognizing-deception in trilwu/secskills) into .claude/skills/recognizing-deception in your project. Claude Code loads it when a task matches its description.

How do I install Recognizing Deception in Codex?

Run `npx skills add trilwu/secskills --skill recognizing-deception -a codex`. Or copy the skill folder (secskills-offense/skills/recognizing-deception in trilwu/secskills) into .agents/skills/recognizing-deception in your project. Codex loads it when a task matches its description.

Can I use Recognizing Deception in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill recognizing-deception -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recognizing-deception, .gemini/skills/recognizing-deception, .github/skills/recognizing-deception and .opencode/skills/recognizing-deception in your project.

What does Recognizing Deception need to run?

Going by SKILL.md and its folder, Recognizing Deception needs the command-line tools its instructions call (curl).

Does Recognizing Deception access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Recognizing Deception safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recognizing Deception use?

Recognizing Deception is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recognizing Deception use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recognizing Deception?

Skills that share tags, products or a category with Recognizing Deception: KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars), Dependency Auditor (alirezarezvani/claude-code-tresor, 777 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars) and Robotics Security (arpitg1304/robotics-agent-skills, 368 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recognizing Deception?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.