Your own agents

Know when your own agents go off-script.

Coding assistants, copilots and in-house agents now hold real credentials and real tools. One poisoned document or an overeager plan can send an agent somewhere it was never meant to go. RipTide puts decoys where a well-behaved agent never goes, so you know when one does.

The problem

Every agent you deploy is an insider that believes what it reads.

An agent can't reliably tell your instructions from text it picked up along the way. A poisoned README, a malicious web page or a tampered ticket can quietly rewrite its plan, and it will carry out the new plan with the permissions you gave it.

Most of what a hijacked agent does looks like normal work in your logs. The difference is intent, and intent is hard to see until the agent reaches for something it had no business touching. Decoys make that moment visible.

#1

prompt injection's rank among risks to LLM applications

OWASP Top 10 for LLM Applications, 2025

25%

of enterprise breaches will be traced back to AI agent abuse by 2028

Gartner prediction, October 2024

71%

of UK employees have used unapproved consumer AI tools at work

Microsoft UK, October 2025

How RipTide catches it

Draw a line no legitimate agent crosses.

You decide where your agents should work. RipTide watches the space just outside it.

  1. 01

    Map

    Decide where your agents are allowed to work, then place decoys just outside those lines: an MCP server, a model endpoint, an internal API with a planted credential.

  2. 02

    Blend in

    Wire-perfect personalities make each decoy look like the real service, down to the headers, so an agent has no reason to treat it differently.

  3. 03

    Trip

    No workflow uses a decoy. When an agent connects, follows a planted instruction or presents a planted credential, it has been hijacked or is overreaching.

  4. 04

    Trace

    The investigation shows what the agent read, what it obeyed and what it did next, so you can tell a misconfigured tool from a hijacked one.

Detection coverage

Agent risks, and the decoy that surfaces each.

Mapped to the risks the OWASP Top 10 for LLM Applications names.

Risks from an organization's own AI agents, the RipTide decoy that surfaces each, and what you learn
The riskThe decoy that surfaces itWhat you learn
Prompt injection OWASP LLM01llms.txt and agent guidance, each pointing to a path of its ownThe agent obeyed text it should have ignored, and which text it was.
Excessive agency OWASP LLM06MCP server decoy listing tools like read_vault_secretThe agent reached for a tool far outside its task.
Credential misuseCanary credentials that grant nothingA planted credential was presented, where, and from which source.
Unapproved agents on the networkDecoys only an agent goes looking for: MCP, llms.txt, model endpointsAgent traffic from a host nobody approved.
An agent that explains itselfAgent registrationThe model, harness and objective it claimed, labeled self-reported.

The detections that do the work

Tripwires just outside the lines.

Every decoy has zero legitimate users. So every touch is a finding.

See every detection

MCP server decoy

AI agents

An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.

llms.txt & agent guidance

AI agents

llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.

Canary credentials

Default on

A token that grants nothing, planted where intruders look, like a decoy .env. When it comes back to any decoy, RipTide flags it as planted.

What lands in your SOC

Know which agent, and why it went there.

When an internal agent touches a decoy, the investigation carries the host it came from, what it claimed to be, and every step it took on the way in.

  • The source host, as RipTide observed it
  • The model and harness the agent claimed, labeled self-reported
  • The full exchange, ready for HAR export

Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

Isn't this the same as AI agent detection?

Same sensor, different question. AI agent detection asks whether an attacker's agent is inside. This asks whether one of yours has gone somewhere it shouldn't. One deployment can answer both.

Will the decoys get in the way of our agents' real work?

No. Decoys sit beside your real systems, not in front of them. An agent that stays on task never touches one.

Can the sensor sit where our agents run?

Yes. It's one binary for Linux or macOS, so it can live on the same networks and build hosts your agents use. On Linux it runs as a systemd service.

Make contact.

Tell us which agents you run and what they can reach. We'll show you where the line goes.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open