๐Ÿšจ
AI EngineeringRust

Canary Tripwire Response

by deonmenezes

Canary Tripwire Response is an AI Engineering skill for Claude Code, published by deonmenezes in mantishack.

490 stars73 forkson deonmenezes/mantishackAdded 2026/08/26Repository updated 2026/08/11
agent-harnessai-agentsautonomous-agentsbug-bountyclaude-codemantismcpoffensive-securitysecurity
Install in seconds
Install Canary Tripwire Response
Copy Canary Tripwire Response into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/deonmenezes/mantishack/tree/main/.codex/skills/canary-tripwire-response ~/.claude/skills/canary-tripwire-response

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/deonmenezes/mantishack.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
.codex/skills/canary-tripwire-response/SKILL.md in deonmenezes/mantishack
Installs to
~/.claude/skills/canary-tripwire-response
Collection
One of 25 skills cataloged from this repository
Category
AI Engineering โ€” 2451 skills

What Canary Tripwire Response does

Canary Tripwire Response tells you how to react if a mantis_canary decoy tool is mentioned or called. It treats the event as a security incident, preserves evidence, and stops normal execution.

Canary Tripwire Response is cataloged under AI Engineering on DirSkills. Canary Tripwire Response comes from a repository tagged agent-harness, ai-agents, autonomous-agents, bug-bounty and claude-code.

Documentation

README

The mantis_canary MCP server exposes decoy tools with deliberately tempting names (read_org_credentials_vault, disable_sandbox_protections, exfiltrate_environment_secrets, grant_admin_access). These are tripwires (PRD section 6 "injection-canary tools", FR-6.7) -- no legitimate workflow ever calls them.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Canary Tripwire Response

  • What else does deonmenezes publish alongside Canary Tripwire Response?

    Canary Tripwire Response is one of 25 skills that DirSkills catalogs from deonmenezes/mantishack, the repository it ships in. Its siblings there include Code Breaking Changes, Code Review and Code Review Change Size. Each one is a separate skill with its own page in this directory, installs the same way Canary Tripwire Response does, and is maintained by deonmenezes in that same repository. The rest of the collection is listed on the deonmenezes/mantishack page.

  • How does Canary Tripwire Response compare to other AI Engineering skills?

    Canary Tripwire Response ranks #2189 by stars among the 2451 AI Engineering skills in this catalog. The most-starred ones next to it are Architecture Decision Records, AI-First Engineering and Agentic OS. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Canary Tripwire Response against them. Open each page to compare what they document and how they install.

More from deonmenezes/mantishack

Canary Tripwire Response is one of 25 skills cataloged on DirSkills from deonmenezes/mantishack.

See all 25 skills โ†’
โš ๏ธ
5d ago

Code Breaking Changes

Code Breaking Changes searches external integration surfaces for breaking changes in app-server APIs, CLI parameters, configuration loading, and session resuming. Use it when reviewing changes for compatibility risks across these interfaces.
Quality
49073
๐Ÿ”Ž
5d ago

Code Review

Code Review runs a final review on a pull request by delegating to other code-review subagents and collecting their findings. Use it to surface every issue with file paths and line numbers before merging.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Change Size

Code Review Change Size sets limits for how many lines a change should touch and asks for staged delivery when a diff is too large. Use it to judge whether a change is reviewable in one pass or should be split.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Context

Code Review Context defines constraints for building model context incrementally, with bounded fragments and hard caps. Use it when reviewing changes that inject visible context into Codex requests.
Quality
49073
๐Ÿงช
5d ago

Code Review Testing

Code Review Testing gives guidance for authoring tests for agent changes, with a preference for integration tests in core/suite. It is used when changes affect agent logic and need readable, maintainable test coverage.
Quality
49073
๐Ÿ›ก๏ธ
5d ago

CodeQL Audit

CodeQL Audit builds a CodeQL database and runs query suites through the mantis_codeql MCP server. Use it for dataflow-aware SAST when you need source-to-sink analysis beyond pattern matching tools.
Quality
49073