Code canaries to quickly triage hallucinated ('slop') vulnerability reports
honeyslop provides decoy source code files in C, Python, and JavaScript that mimic vulnerabilities to help developers triage and dismiss AI-generated false positive security reports.
How It Works
You're maintaining an open-source project and keep getting flooded with nonsense vulnerability reports from AI tools.
You learn about honeyslop, a smart collection of decoy files designed to catch and expose those fake reports.
Copy the special decoy files into your project's folders, disguised as old legacy code.
Adjust your project's build and checking tools to skip over these harmless decoys so they don't cause false alarms for you.
Add simple check rules to your project's security notes to instantly spot and close fake reports.
Fake AI reports now trip over the decoys, making them easy to dismiss while real issues stand out.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.