Observed arrival · 2026-10-01
Lilytrap turns code into an AI-agent honeypot
Lilytrap offers a GitHub Action that plants decoy files and credentials during builds, then alerts teams if an AI coding agent uses them.
- For
- Teams building software with AI coding agents
- Worth noticing
- The sample alert traces a decoy support key from a trail comment to a handoff note, then offers an IP-blocking action.
Field notes
The homepage shows a release workflow in which lilytrap/lilytrap@v0 runs after npm run build, with six honeypots planted before deployment. Its sample alert traces a decoy support key through a trail comment and handoff note; the page also displays Free, Team ($20/month), and Business ($99/month) tiers. The site says its optional agent hand-off token is limited to Actions: write, but these are product descriptions, not independently verified behavior.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue