Skip to main content

recognizing-deception

Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and telltale patterns so a planted tripwire does not burn the operation. Use before acting on found credentials, roasting an SPN, or opening a too-convenient file. Unattributable access is a trap until proven otherwise; if you cannot say where it came from, do not use it.

Jump to install

Source facts

Repository
EvilFreelancer/secs
Last source activity
August 8, 2026 at 20:56
Detected SKILL.md language
English
Stars
9
Forks
2

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.