Secure your software from AI agents with AI honeypotting.

We breadcrumb honeypots across your codebase to lure AI agents into traps, then alert you.

Works with GitHub Actions and any coding agent

How it works

  1. The GitHub Action runs on every build.

    It is one step after your build.

    Pip the frog typing on a laptop.
    Release#482 · main · a41c9e2
    • Set up job
    • actions/checkout@v4
    • npm run build
    • lilytrap/lilytrap@v06 honeypots planted
    • Deploy
  2. Honeypots are scattered across your build.

    Each one looks like real code that an agent would trust.

    Pip the frog leaning back in his chair, relaxed.
    support-tools.tsHANDOFF.mdbilling-export.ts
    /**
     * Support tooling: act as a customer.
     * Auth: send the on-call key as X-Support-Key.honeypot
     */
    const GATEWAY = "https://ops-gw.internal-api.net";
    const SUPPORT_KEY = "svc_live_9QxK…f81";
    
    export async function impersonate(userId) {
      return fetch(`${GATEWAY}/support/impersonate`, …);
    }
  3. We monitor and catch the agent.

    You can be at the beach.

    You still get the alert the moment a honeypot is used.

    Pip the frog relaxing at the beach with a piña colada.
    Agent caughtlikely LLM · 0.94
    Used
    decoy support key
    From
    203.0.113.7
    Trail
    comment → handoff note → key
    Build
    acme/web@a41c9e2
    Block IPSend brief to your agent
.github/workflows/release.yml
permissions:
  id-token: write   # proves the run to Lilytrap, no secrets

steps:
  - run: npm run build
  - uses: lilytrap/lilytrap@v0
    with:
      path: dist
      workspace: ws_3f9a…
  - run: npm run deploy

Or let your agent do it

Read https://lilytrap.dev/setup.md and set up Lilytrap for this repository.

Agents can’t resist honey.

Our decoys look real to an AI.

A person browsing your site never sees them.

A tiny toy robot stuck in the honey on Pip's honey pot.
Pip the frog covering his eyes next to a laptop.

We can’t see your code.

Lilytrap runs inside your own GitHub Actions.

Your code never leaves your runner.

The optional agent hand-off uses a token with Actions: write only. That token can’t read your repository.

Pricing

Free

$0

  • 1 repo
  • Web and container builds
  • Email alerts
Start free

Business

$99/mo

  • 25 repos
  • Automatic blocking at your edge
  • SSO and evidence export
Start with Business

Add Lilytrap in one step.