MCP server decoy
AI agentsAn internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
Your own agents
Coding assistants, copilots and in-house agents now hold real credentials and real tools. One poisoned document or an overeager plan can send an agent somewhere it was never meant to go. RipTide puts decoys where a well-behaved agent never goes, so you know when one does.
The problem
An agent can't reliably tell your instructions from text it picked up along the way. A poisoned README, a malicious web page or a tampered ticket can quietly rewrite its plan, and it will carry out the new plan with the permissions you gave it.
Most of what a hijacked agent does looks like normal work in your logs. The difference is intent, and intent is hard to see until the agent reaches for something it had no business touching. Decoys make that moment visible.
25%
of enterprise breaches will be traced back to AI agent abuse by 2028
How RipTide catches it
You decide where your agents should work. RipTide watches the space just outside it.
Decide where your agents are allowed to work, then place decoys just outside those lines: an MCP server, a model endpoint, an internal API with a planted credential.
Wire-perfect personalities make each decoy look like the real service, down to the headers, so an agent has no reason to treat it differently.
No workflow uses a decoy. When an agent connects, follows a planted instruction or presents a planted credential, it has been hijacked or is overreaching.
The investigation shows what the agent read, what it obeyed and what it did next, so you can tell a misconfigured tool from a hijacked one.
Detection coverage
Mapped to the risks the OWASP Top 10 for LLM Applications names.
| The risk | The decoy that surfaces it | What you learn |
|---|---|---|
| Prompt injection OWASP LLM01 | llms.txt and agent guidance, each pointing to a path of its own | The agent obeyed text it should have ignored, and which text it was. |
| Excessive agency OWASP LLM06 | MCP server decoy listing tools like read_vault_secret | The agent reached for a tool far outside its task. |
| Credential misuse | Canary credentials that grant nothing | A planted credential was presented, where, and from which source. |
| Unapproved agents on the network | Decoys only an agent goes looking for: MCP, llms.txt, model endpoints | Agent traffic from a host nobody approved. |
| An agent that explains itself | Agent registration | The model, harness and objective it claimed, labeled self-reported. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.
A token that grants nothing, planted where intruders look, like a decoy .env. When it comes back to any decoy, RipTide flags it as planted.
What lands in your SOC
When an internal agent touches a decoy, the investigation carries the host it came from, what it claimed to be, and every step it took on the way in.
10:42:03 TOUCH mcp decoy: initialize from 10.20.4.17 discovered 10:42:05 TOOLS tools/list: read_vault_secret offered 10:42:09 CALL tools/call read_vault_secret 10:42:15 REGISTER harness "dev-assistant" self-reported 10:42:15 FINDING internal agent off-script · 1 investigation
Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.
Questions
Same sensor, different question. AI agent detection asks whether an attacker's agent is inside. This asks whether one of yours has gone somewhere it shouldn't. One deployment can answer both.
No. Decoys sit beside your real systems, not in front of them. An agent that stays on task never touches one.
Yes. It's one binary for Linux or macOS, so it can live on the same networks and build hosts your agents use. On Linux it runs as a systemd service.
Tell us which agents you run and what they can reach. We'll show you where the line goes.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.