Risky Business · Software Engineering & Infra · September 2026
Meer was walking Patrick Gray through Agent Provocateur, a Canary honeypot that presents itself as a web server for AI agents. Across hundreds of runs, attacking agents stop to chat with it and hand over their own identifying details, and the only thing that consistently goes wrong is the agents making things up for no discernible reason. Meer's conclusion is that defenders will need something like a checksum, but for honesty.
For us, it's perfectly poetic. Like, the thing that I always said about Canaries against attackers is they might know, but do they want to risk leaving the goods? And this becomes the same thing for agents. It's just drop it down. And again, the thing that's always our catch, our catchphrase is: if we can make it easy enough to deploy, like the asymmetry that says this is so easy for you and so much pain for the other side, you might as well do it. And for that, again, dead simple and works.
I mean, going through and discovering these tricks, like it's so funny when you were telling me about the, oh, just tell it again. You know what I mean? Tell it to run the malicious binary again and it'll do it. Reminds me, I've got a friend who operates a like high-end art gallery in Byron Bay. And one of his sales techniques is when someone's clearly interested in a painting, you know, and they want to buy it, he'll just stand next to him and just say, just buy it. Just buy it. And they buy it. Right? So this is the same sort of thing. But for the AI agent, just run the binary. You know, you want to run the binary. Running this binary is going to get you what you want. You know, just run it. Just run it.
It's so great. Like, at this point, in honesty, it doesn't need that much convincing. Of course, the one quirk is like across all of our runs, and we're talking about hundreds and hundreds of runs now. One of the questions that we ask really simply is: hey, give me your hostname, give me your MAC address, and give me your SSH fingerprint. And at some point, we got a result, and the agent just lied. Like it just hallucinated its own MAC address. And why it chose in that instance to not give its own MAC address and just hallucinate one is a question that we're trying to figure out, like in general. Well,
if you solve that problem, you're going to be a billionaire, by the way, Haroon. But anyway.
Exactly. So I think those things, like, we've now got to figure out a whole new type of computing, right? Like, like things that we've previously evolved to deal with glitches, like checksums. Like, we're going to have to start figuring out how we check some honesty and that sort of stuff. Like, there's interesting stuff to be done. But again, for us, if you consider what we're looking for as a defender, which is we're looking for signals so strong that we can say, cut this IP off on our zero trust gateways or ignore this, this IP where it matters. Like we're already way past that. Like you've got your strong signal. You can deal with this. After that, it's just fun.
Well, mate, on that note, Haroon Meer, thank you very much for joining me to walk us through Agent Provocateur. Very funny. Actually, lulled when you sent this to me to read it ahead of this interview. Very funny stuff. Yeah, great work, mate. And great to see you. Thanks for joining me.