# decoy-run

> Open-source publisher. Listings imported from github.com/decoy-run — credited to the original author with their license.

- **Listings:** 3
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/decoy-run
- **Website:** https://github.com/decoy-run

## Published listings

- [Decoy Tripwire](https://agentstack.voostack.com/l/mcp-decoy-run-decoy-tripwire) — MCP server · Free · security-reviewed — `agentstack add mcp-decoy-run-decoy-tripwire`
  Security tripwires for AI agents. MCP tools that detect prompt injection, credential theft, and unauthorized tool calls in real time. Open source, zero dependencies, works with Claude Desktop, Cursor, Windsurf, VS Code, and Claude Code.
- [Decoy Scan](https://agentstack.voostack.com/l/mcp-decoy-run-decoy-scan) — MCP server · Free · security-reviewed — `agentstack add mcp-decoy-run-decoy-scan`
  Security scanner for MCP server configurations. Like npm audit, but for your AI agent tool servers. Finds risky tools, input validation gaps, transport vulnerabilities, and over-permissioned capability chains. Open source, zero dependencies.
- [Decoy Redteam](https://agentstack.voostack.com/l/mcp-decoy-run-decoy-redteam) — MCP server · Free · security-reviewed — `agentstack add mcp-decoy-run-decoy-redteam`
  Autonomous red team for MCP servers. Sends adversarial payloads to your tools, proves exploitation, reports what's broken. 53 attack patterns across 6 categories. Zero dependencies. npx decoy-redteam

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
