Documentation
¶
Overview ¶
Command honeytool is a self-contained, runnable demonstration of using Legant as INTRUSION DETECTION for AI agents. You front an MCP server with the gateway and salt it with "honeytools" — tools the agent was never delegated, left VISIBLE in tools/list as bait. A well-behaved agent never touches them. But a prompt-injected or compromised agent that reaches for one is denied AND leaves a tamper-evident, provenance-stamped forensic record naming exactly who tried what for whom — without ever touching real data.
No database, no Docker:
go run ./examples/honeytool # or make demo-honeytool
Click to show internal directories.
Click to hide internal directories.